CVE-2002-1786: Low severity sgi irix vulnerability
Published Dec 31, 2002
·Updated
SGI IRIX 6.5 through 6.5.14 applies a umask of 022 to root core dumps, which allows local users to read the core dumps and possibly obtain sensitive information.
Affected Software
15 affected components
SGI IRIX=6.5.6
SGI IRIX=6.5.1
SGI IRIX=6.5.10
SGI IRIX=6.5.12
SGI IRIX=6.5.9
SGI IRIX=6.5.3
SGI IRIX=6.5.14
SGI IRIX=6.5.8
SGI IRIX=6.5.5
SGI IRIX=6.5.4
SGI IRIX=6.5.11
SGI IRIX=6.5.2
SGI IRIX=6.5
SGI IRIX=6.5.7
SGI IRIX=6.5.13
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Jun 28, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1786?
CVE-2002-1786 has a moderate severity rating due to the exposure of sensitive information.
2
How do I fix CVE-2002-1786?
Fix CVE-2002-1786 by changing the umask for root core dumps to a more restrictive value.
3
What software versions are affected by CVE-2002-1786?
CVE-2002-1786 affects SGI IRIX versions 6.5 through 6.5.14.
4
Can local users exploit CVE-2002-1786?
Yes, local users can exploit CVE-2002-1786 to read root core dumps and potentially access sensitive information.
5
Is CVE-2002-1786 related to file permissions?
Yes, CVE-2002-1786 is directly related to the umask setting that affects file permissions for root core dumps.