CVE Vulnerabilities

CVE-2002-2334

Published: Dec 31, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.

Affected Software

Name Vendor Start Version End Version
Joe Joseph_allen 2.8 (including) 2.8 (including)
Joe Joseph_allen 2.9 (including) 2.9 (including)
Joe Joseph_allen 2.9.1 (including) 2.9.1 (including)
Joe Joseph_allen 2.9.2 (including) 2.9.2 (including)
Joe Joseph_allen 2.9.4 (including) 2.9.4 (including)
Joe Joseph_allen 2.9.5 (including) 2.9.5 (including)
Joe Joseph_allen 2.9.6 (including) 2.9.6 (including)
Joe Joseph_allen 2.9.7 (including) 2.9.7 (including)

References