CVE Vulnerabilities

CVE-2002-0572

Published: Jul 03, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.

Affected Software

NameVendorStart VersionEnd Version
FreebsdFreebsd4.4-releng (including)4.4-releng (including)
FreebsdFreebsd4.5-release (including)4.5-release (including)
FreebsdFreebsd4.5-stable (including)4.5-stable (including)
OpenbsdOpenbsd2.0 (including)2.0 (including)
OpenbsdOpenbsd2.1 (including)2.1 (including)
OpenbsdOpenbsd2.2 (including)2.2 (including)
OpenbsdOpenbsd2.3 (including)2.3 (including)
SolarisSun2.5.1 (including)2.5.1 (including)
SolarisSun2.6 (including)2.6 (including)
SolarisSun7.0 (including)7.0 (including)
SolarisSun8.0 (including)8.0 (including)
SunosSun- (including)- (including)
SunosSun5.5.1 (including)5.5.1 (including)
SunosSun5.7 (including)5.7 (including)
SunosSun5.8 (including)5.8 (including)

References