CVE-2000-1103

BSD 3.0 and 4.0 - Privilege Escalation via rcvtty Script Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-1103. PoCs published by vade79.

AI-analyzed exploit summary This exploit targets a local privilege escalation vulnerability in the rcvtty binary of the mh package on BSDi systems. It leverages the setgid bit to create a shell with egid=4 (tty), allowing the attacker to gain elevated group privileges.

Description

rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.

Exploits (1)

exploitdb WORKING POC VERIFIED
by vade79 · clocalbsd
https://www.exploit-db.com/exploits/202

This exploit targets a local privilege escalation vulnerability in the rcvtty binary of the mh package on BSDi systems. It leverages the setgid bit to create a shell with egid=4 (tty), allowing the attacker to gain elevated group privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: mh package (rcvtty binary) on BSDi 3.0/4.0
No auth needed
Prerequisites: Local access to the system · rcvtty binary must be setgid
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/147120
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2009

Scores

EPSS 0.0094
EPSS Percentile 56.3%

Details

Status published
Products (4)
bsdi/bsd_os 3.0
bsdi/bsd_os 3.1
bsdi/bsd_os 4.0
bsdi/bsd_os 4.0.1
Published Jan 09, 2001
Tracked Since Feb 18, 2026