CVE-2002-0435
 
Severity Score
1.2
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2002-06-07 CVE Reserved
- 2002-07-26 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://mail.gnu.org/archive/html/bug-fileutils/2002-03/msg00028.html | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-018.1.txt | 2008-09-05 | |
http://www.iss.net/security_center/static/8432.php | 2008-09-05 | |
http://www.securityfocus.com/bid/4266 | 2008-09-05 |
URL | Date | SRC |
---|---|---|
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-031.php | 2008-09-05 | |
http://www.redhat.com/support/errata/RHSA-2003-015.html | 2008-09-05 | |
http://www.redhat.com/support/errata/RHSA-2003-016.html | 2008-09-05 | |
http://www.securityfocus.com/archive/1/260936 | 2008-09-05 | |
https://access.redhat.com/security/cve/CVE-2002-0435 | 2003-02-20 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1616780 | 2003-02-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnu Search vendor "Gnu" | Fileutils Search vendor "Gnu" for product "Fileutils" | 4.0 Search vendor "Gnu" for product "Fileutils" and version "4.0" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Fileutils Search vendor "Gnu" for product "Fileutils" | 4.1 Search vendor "Gnu" for product "Fileutils" and version "4.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Fileutils Search vendor "Gnu" for product "Fileutils" | 4.1.6 Search vendor "Gnu" for product "Fileutils" and version "4.1.6" | - |
Affected
|