CVE-2000-1074
High
High exploit probability or critical severity with a known exploit.
CVSS base
10.0
HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS — probability of exploitation (30 days)
4.1%
90.4th percentile
CISA KEV
Not listed
Weakness / dates
—
Published 2000-12-11 · modified 2026-09-23
CVSS breakdown
AV:N/AC:L/Au:N/C:C/I:C/A:C
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Authentication | N | None |
| Confidentiality | C | Complete |
| Integrity | C | Complete |
| Availability | C | Complete |
Timeline
- 2000-12-11 — Published (NVD)
- 2026-09-23 — Last modified (NVD)
Description
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.
Affected
References
- exploit http://www.atstake.com/research/advisories/2000/a100900-1.txt
- http://www.osvdb.org/7209
- exploit http://www.securityfocus.com/bid/1769
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5757
- exploit http://www.atstake.com/research/advisories/2000/a100900-1.txt
- http://www.osvdb.org/7209
- exploit http://www.securityfocus.com/bid/1769
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5757