First published: Wed Jul 03 2002(Updated: )
mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenBSD | =2.9 | |
OpenBSD | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0542 is classified as a high severity vulnerability due to its potential for local users to gain root privileges.
To fix CVE-2002-0542, upgrade to a version of OpenBSD that is not affected, specifically version 3.1 or later.
CVE-2002-0542 affects OpenBSD versions 2.9 and 3.0.
CVE-2002-0542 enables local users to execute commands with root privileges via the mail program in cron jobs.
Disabling the mail service or restricting access to it can serve as a temporary workaround for CVE-2002-0542.