First published: Mon Aug 12 2002(Updated: )
BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Point-to-Point Protocol Daemon | ||
Point-to-Point Protocol (PPP) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0824 is considered a moderate severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2002-0824, users should update the Point-to-Point Protocol daemon to the latest version or apply the appropriate security patches.
CVE-2002-0824 involves a symlink attack that enables local users to change the permissions of arbitrary files.
CVE-2002-0824 affects the Point-to-Point Protocol daemon in FreeBSD.
No, CVE-2002-0824 can only be exploited by local users with the ability to create symlinks.