CVE-2002-0761: Low severity Bzip bzip2 vulnerability
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an archive, which could cause the files to be extracted with less restrictive permissions than intended.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0761?
CVE-2002-0761 is considered a moderate severity vulnerability due to its potential impact on file permissions.
How do I fix CVE-2002-0761?
To fix CVE-2002-0761, upgrade bzip2 to version 1.0.2 or later.
What systems are affected by CVE-2002-0761?
CVE-2002-0761 affects bzip2 versions prior to 1.0.2 on FreeBSD 4.5 and older, and OpenLinux 3.1 and 3.1.1.
What types of vulnerabilities are present in CVE-2002-0761?
CVE-2002-0761 introduces vulnerabilities related to incorrect file permission handling through symbolic links during archive creation.
Is there a workaround for CVE-2002-0761?
There are no specific workarounds for CVE-2002-0761; the recommended action is to upgrade to a patched version of bzip2.