CVE-2000-0378

CVSS 2.0 Score 7.2 of 10 (high)

Details

Published May 3, 2000
Updated: Nov 20, 2024

Summary

CVE-2000-0378 is a vulnerability affecting the pam_console PAM module in Linux systems. Upon user login, this module performs a chown operation on various devices, but fails to close open file descriptors properly. As a result, a user who has previously logged in can retain access to these devices and potentially eavesdrop on subsequent users' activities. This issue poses a significant security risk, particularly in multi-user environments. It is recommended that system administrators update their Linux distributions to the latest version, which includes a fix for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Red Hat Enterprise Linux

Affected Vendors

  • Red Hat