20020613 simpleinit root exploit - file descriptor left openmailing list
http://online.securityfocus.com/archive/1/276739 CVE-2002-0767
Richard Gooch SimpleInit 2.0.2 - Open File Descriptor
Record summary
CVE-2002-0767 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with root privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRichard Gooch SimpleInit 2.0.2 - Open File DescriptorExploitDB exploitby Patrick SmithNot analyzed1 file
References
4simpleinit-file-descriptor-open(9357)vdb entry
http://www.iss.net/security_center/static/9357.php 5001vdb entry
http://www.securityfocus.com/bid/5001 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0767