CVE-2002-1509: Low severity redhat Linux vulnerability
A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of the new user's group (mode 660), which allows other users in the same group to read or modify the new user's incoming email.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1509?
CVE-2002-1509 is considered a moderate severity vulnerability due to the potential unauthorized access to users' incoming email.
How do I fix CVE-2002-1509?
To fix CVE-2002-1509, update to the latest version of shadow-utils or adjust the permissions on the mail spool files to restrict access.
Which versions of Red Hat Linux are affected by CVE-2002-1509?
CVE-2002-1509 affects Red Hat Linux versions 7.2, 8.0, and 7.3.
What does CVE-2002-1509 exploit?
CVE-2002-1509 exploits improper permissions on mail spool files created by the useradd command.
Who can be impacted by CVE-2002-1509?
Users in the same group as the newly created user can read or modify that user's incoming email due to this vulnerability.