First published: Tue Dec 31 2002(Updated: )
pkg_add in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package during installation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =4.2 | |
FreeBSD Kernel | =4.3 | |
FreeBSD Kernel | =4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1669 has a moderate severity rating due to the potential for local users to manipulate package installations.
To mitigate CVE-2002-1669, ensure that the temporary directory created by pkg_add has appropriate permissions set to prevent world-searchable access.
CVE-2002-1669 affects FreeBSD versions 4.2, 4.3, and 4.4.
CVE-2002-1669 may allow local users to modify parts of the package during installation due to insecure temporary directory permissions.
CVE-2002-1669 is a local vulnerability that requires access to the system to exploit.