CVE detail
CVE-2001-1029 — CVE-2001-1029
Published 2001-09-20 · Modified 2026-06-16 · Vendor openbsd · Product openssh · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0137
EPSS probability
exploitation probability, 30d
69.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References