CVE-2002-2382: High severity cvsup cvsup vulnerability
Published Dec 31, 2002
·Updated
cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on /var/tmp/cvsupd.out.
Affected Software
1 affected component
cvsup cvsup=1.2
Remediation
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 31, 2007
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2382?
CVE-2002-2382 has a high severity rating as it allows local users to overwrite arbitrary files and gain elevated privileges.
2
How do I fix CVE-2002-2382?
To fix CVE-2002-2382, upgrade CVSup to a version later than 1.2 that does not contain this vulnerability.
3
Who is affected by CVE-2002-2382?
CVE-2002-2382 affects local users who have access to the CVSup 1.2 application.
4
What type of attack is CVE-2002-2382 associated with?
CVE-2002-2382 is associated with a symlink attack that exploits the way files are handled in CVSup 1.2.
5
What are the potential impacts of CVE-2002-2382?
The potential impacts of CVE-2002-2382 include unauthorized file overwriting and possible privilege escalation for local users.