2.1

CVE-2002-0080

rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samba ≫ Rsync Version < 2.5.3
Redhat ≫ Linux Version 6.2
Redhat ≫ Linux Version 7.0
Redhat ≫ Linux Version 7.1
Redhat ≫ Linux Version 7.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.419
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

http://www.caldera.com/support/security/advisories/CSSA-2002-014.1.txt
Broken Link
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-024.php3
Broken Link
http://www.redhat.com/support/errata/RHSA-2002-026.html
Patch
Third Party Advisory
http://www.iss.net/security_center/static/8463.php
Broken Link
http://www.securityfocus.com/bid/4285
Third Party Advisory
VDB Entry