CVE-2001-0859 describes a vulnerability in the 2.4.3-12 kernel of Red Hat Linux 7.1 Korean installation program. It incorrectly sets the default umask for init to 000, resulting in newly installed files having world-writable permissions. This medium-severity vulnerability (CVSS 5.0) can be exploited remotely with low complexity, leading to potential integrity impacts as unauthorized users could modify system files. There is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1CPE matchmatch criteria | cpe:2.3:o:redhat:linux:7.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.