CVE-2002-0557: High severity OpenBSD OpenBSD vulnerability
Published Jun 11, 2002
·Updated
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to authapproval().
Affected Software
1 affected component
OpenBSD OpenBSD=3.0
Remediation
Patch Available
Patch Available
Event History
Jun 11, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0557?
CVE-2002-0557 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2002-0557?
To mitigate CVE-2002-0557, upgrade to a patched version of OpenBSD beyond 3.0.
3
What are the potential impacts of CVE-2002-0557?
CVE-2002-0557 may allow unauthorized users to execute commands or access directories belonging to other users.
4
Which versions of OpenBSD are affected by CVE-2002-0557?
CVE-2002-0557 specifically affects OpenBSD version 3.0.
5
What services are impacted by CVE-2002-0557?
CVE-2002-0557 impacts the rexec and rsh services, as well as the atrun command.