First published: Wed Feb 27 2002(Updated: )
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SCO OpenLinux Server | =3.1 | |
SCO OpenLinux Workstation | =3.1 | |
Red Hat Linux | =7.2 | |
Debian GNU/Linux | =2.2 | |
SUSE Linux | =7.1 | |
Red Hat Linux | =6.2 | |
SUSE Linux | =7.1-alpha | |
Slackware Linux | =8.0 | |
Slackware Linux | =7.1 | |
Mandrake Linux | =8.1 | |
Debian GNU/Linux | =2.2 | |
Red Hat Linux | =7.1 | |
SUSE Linux | =7.3 | |
SUSE Linux | =7.1 | |
SUSE Linux | =7.0 | |
SUSE Linux | =6.4 | |
SUSE Linux | =7.3 | |
Red Hat Linux | =7.0 | |
FreeBSD FreeBSD | =4.4 | |
Red Hat Linux | =7.2 | |
Mandrake Linux | =8.1 | |
Slackware Linux | =7.0 | |
Red Hat Linux | =6.2 | |
SUSE Linux | =7.0 | |
SUSE Linux | =7.0 | |
Mandrake Linux | =8.0 | |
Debian GNU/Linux | =2.2 | |
Red Hat Linux | =7.1 | |
SUSE Linux | =6.4 | |
Red Hat Linux | =7.1 | |
NetBSD NetBSD | =1.5.2 | |
FreeBSD FreeBSD | =4.2 | |
Debian GNU/Linux | =2.2 | |
SUSE Linux | =7.0-alpha | |
FreeBSD FreeBSD | =4.1.1 | |
Red Hat Linux | =6.2 | |
FreeBSD FreeBSD | =4.3 | |
SUSE Linux | =6.4-alpha | |
Mandrake Linux | =8.0 | |
Red Hat Linux | =7.0 | |
SUSE Linux | =7.2 | |
SUSE Linux | =7.3 | |
Red Hat Linux | =7.2 | |
Debian GNU/Linux | =2.2 | |
SUSE Linux | =7.1 | |
Debian GNU/Linux | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0004 is considered a high severity vulnerability due to its potential to allow local users to execute arbitrary code.
To fix CVE-2002-0004, update the affected software to a version that has addressed this heap corruption vulnerability.
CVE-2002-0004 affects several systems including SCO OpenLinux Server 3.1, Red Hat Linux 6.2 through 7.2, and Debian Linux 2.2.
Exploitation of CVE-2002-0004 typically involves passing a malformed execution time to the "at" program to trigger memory corruption.
Yes, CVE-2002-0004 can be exploited by local users, making it relatively easy for malicious actors with local access to take advantage of the vulnerability.