CVE-2002-0525: Critical severity ISC inn vulnerability
Published Jun 11, 2002
·Updated
Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.
Affected Software
6 affected components
ISC inn=2.2
ISC inn=2.2.2
ISC inn=2.0
ISC inn=2.1
ISC inn=2.2.1
ISC inn=2.2.3
Remediation
Patch Available
Event History
Jun 11, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0525?
CVE-2002-0525 is classified as a medium-severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2002-0525?
To mitigate CVE-2002-0525, update to a patched version of ISC INN that resolves the format string vulnerabilities.
3
Which versions of ISC INN are affected by CVE-2002-0525?
ISC INN versions 2.0, 2.1, 2.2, 2.2.1, 2.2.2, and 2.2.3 are affected by CVE-2002-0525.
4
Can CVE-2002-0525 be exploited remotely?
Yes, CVE-2002-0525 can be exploited remotely by malicious NNTP servers.
5
What types of attacks can CVE-2002-0525 facilitate?
CVE-2002-0525 can facilitate local privilege escalation for users exploiting format string vulnerabilities.