CVE-2002-0795: Low severity FreeBSD FreeBSD vulnerability
Published Aug 12, 2002
·Updated
The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files.
Affected Software
2 affected components
FreeBSD FreeBSD=4.5-stable
FreeBSD FreeBSD=4.5-release
Remediation
Patch Available
Patch Available
Event History
Aug 12, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0795?
CVE-2002-0795 is considered to be a moderate severity vulnerability.
2
How do I fix CVE-2002-0795?
To fix CVE-2002-0795, upgrade to FreeBSD version 4.6 or later where the issue is resolved.
3
What types of systems are affected by CVE-2002-0795?
CVE-2002-0795 affects FreeBSD versions 4.5-release and 4.5-stable.
4
What is a symlink attack in relation to CVE-2002-0795?
A symlink attack in this context allows local users to exploit vulnerabilities in file permission settings to delete arbitrary files.
5
Who can exploit CVE-2002-0795?
CVE-2002-0795 can be exploited by local users on the FreeBSD system.