20001206 apcupsd 3.7.2 Denial of Servicemailing list
http://archives.neohapsis.com/archives/bugtraq/2000-12/0066.html CVE-2001-0040
APC UPS 3.7.2 - 'apcupsd' Local Denial of Service
Record summary
CVE-2001-0040 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAPC UPS 3.7.2 - 'apcupsd' Local Denial of ServiceExploitDB exploitby the itchNot analyzed1 file
References
5MDKSA-2000:077Vendor advisory
http://www.linux-mandrake.com/en/security/MDKSA-2000-077.php3 2070vdb entry
http://www.securityfocus.com/bid/2070 apc-apcupsd-dos(5654)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5654 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0040