CVE-2002-2092: Race Condition
Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or setgid.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2092?
CVE-2002-2092 is considered a high severity vulnerability as it allows local users to gain elevated privileges.
How do I fix CVE-2002-2092?
To fix CVE-2002-2092, update your OpenBSD, NetBSD, or FreeBSD systems to versions that have patched the vulnerability.
Who is affected by CVE-2002-2092?
CVE-2002-2092 affects local users of OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier.
How does CVE-2002-2092 exploit the system?
CVE-2002-2092 exploits a race condition in the exec function by allowing users to attach a debugger before the kernel sets the process's privileges.
What systems are vulnerable to CVE-2002-2092?
The systems vulnerable to CVE-2002-2092 include specific versions of OpenBSD, FreeBSD, and NetBSD prior to the patched versions.