CVE-2002-0754: High severity FreeBSD Heimdal vulnerability
Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0754?
CVE-2002-0754 is considered a high-severity vulnerability because it can allow unauthorized users to regain root privileges.
How do I fix CVE-2002-0754?
To fix CVE-2002-0754, it is recommended to upgrade to a patched version of FreeBSD or Heimdal that addresses this vulnerability.
What versions are affected by CVE-2002-0754?
CVE-2002-0754 affects FreeBSD versions 4.0 to 4.4 and Heimdal version 0.4e.
What type of vulnerability is CVE-2002-0754?
CVE-2002-0754 is a privilege escalation vulnerability that exploits the getlogin() system call in FreeBSD.
Can CVE-2002-0754 be exploited remotely?
CVE-2002-0754 typically requires local access to the system to exploit, making it less likely to be remotely exploited.