CVE-2002-0542: High severity OpenBSD OpenBSD vulnerability
Published Jul 3, 2002
·Updated
mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.
Affected Software
2 affected components
OpenBSD OpenBSD=2.9
OpenBSD OpenBSD=3.0
Remediation
Patch Available
Patch Available
Event History
Jul 3, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0542?
CVE-2002-0542 is classified as a high severity vulnerability due to its potential for local users to gain root privileges.
2
How do I fix CVE-2002-0542?
To fix CVE-2002-0542, upgrade to a version of OpenBSD that is not affected, specifically version 3.1 or later.
3
What systems are affected by CVE-2002-0542?
CVE-2002-0542 affects OpenBSD versions 2.9 and 3.0.
4
What exploit does CVE-2002-0542 enable?
CVE-2002-0542 enables local users to execute commands with root privileges via the mail program in cron jobs.
5
Is there a workaround for CVE-2002-0542?
Disabling the mail service or restricting access to it can serve as a temporary workaround for CVE-2002-0542.