LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2001-1029

CVE-2001-1029

CVSS 2.1 · LOW

Summary

libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.

CVSS 2.0 breakdown

Base score2.1 (LOW)
VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Attack vectorLOCAL
Attack complexityLOW
ConfidentialityPARTIAL
IntegrityNONE
AvailabilityNONE

Affected products

Openbsd opensshFreebsd freebsd
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.

Scroll to Top