CVE-2002-1669: Low severity FreeBSD FreeBSD vulnerability
Published Dec 31, 2002
·Updated
pkgadd in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package during installation.
Affected Software
3 affected components
FreeBSD FreeBSD=4.2
FreeBSD FreeBSD=4.3
FreeBSD FreeBSD=4.4
Remediation
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Jun 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1669?
CVE-2002-1669 has a moderate severity rating due to the potential for local users to manipulate package installations.
2
How do I fix CVE-2002-1669?
To mitigate CVE-2002-1669, ensure that the temporary directory created by pkg_add has appropriate permissions set to prevent world-searchable access.
3
Which versions of FreeBSD are affected by CVE-2002-1669?
CVE-2002-1669 affects FreeBSD versions 4.2, 4.3, and 4.4.
4
What type of attack does CVE-2002-1669 enable?
CVE-2002-1669 may allow local users to modify parts of the package during installation due to insecure temporary directory permissions.
5
Is CVE-2002-1669 a remote or local vulnerability?
CVE-2002-1669 is a local vulnerability that requires access to the system to exploit.