CVE-2001-0220

ja-elvis and ko-helvis - Local Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0220. PoCs published by dethy.

AI-analyzed exploit summary This exploit targets a buffer overflow in the 'elvrec' utility from ja-elvis and ko-helvis packages on FreeBSD, allowing local privilege escalation to root. It uses a standard stack-based overflow with NOP sled and shellcode to spawn a root shell.

Description

Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.

Exploits (1)

exploitdb WORKING POC VERIFIED
by dethy · clocalbsd
https://www.exploit-db.com/exploits/287

This exploit targets a buffer overflow in the 'elvrec' utility from ja-elvis and ko-helvis packages on FreeBSD, allowing local privilege escalation to root. It uses a standard stack-based overflow with NOP sled and shellcode to spawn a root shell.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: ja-elvis < 1.8.4_1, ko-helvis < 1.8h2_1 on FreeBSD
No auth needed
Prerequisites: Local access to the vulnerable system · Presence of vulnerable ja-elvis or ko-helvis package
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Patch, Vendor Advisory vendor-advisory x_refsource_freebsd
http://archives.neohapsis.com/archives/freebsd/2001-02/0082.html

Scores

EPSS 0.0090
EPSS Percentile 55.2%

Details

Status published
Products (2)
ja-elvis/ja-elvis < 1.8.4_1
ko-helvis/ko-helvis < 1.8h2_1
Published Jun 02, 2001
Tracked Since Feb 18, 2026