6.2

CVE-2002-0638

setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpSecure Os Version1.0 Editionlinux
MandrakesoftMandrake Linux Version7.0
MandrakesoftMandrake Linux Version7.1
MandrakesoftMandrake Linux Version7.2
MandrakesoftMandrake Linux Version8.0
MandrakesoftMandrake Linux Version8.0 Editionppc
MandrakesoftMandrake Linux Version8.1
MandrakesoftMandrake Linux Version8.1 Editionia64
MandrakesoftMandrake Linux Version8.2
RedhatLinux Version6.0
RedhatLinux Version6.0 Editionalpha
RedhatLinux Version6.0 Editionsparc
RedhatLinux Version6.1
RedhatLinux Version6.1 Editionalpha
RedhatLinux Version6.1 Editionsparc
RedhatLinux Version6.2
RedhatLinux Version6.2 Editionalpha
RedhatLinux Version6.2 Editionsparc
RedhatLinux Version7.0
RedhatLinux Version7.0 Editionalpha
RedhatLinux Version7.1
RedhatLinux Version7.1 Editionalpha
RedhatLinux Version7.1 Editionia64
RedhatLinux Version7.2
RedhatLinux Version7.2 Editionalpha
RedhatLinux Version7.2 Editionia64
RedhatLinux Version7.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.217
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.2 1.9 10
AV:L/AC:H/Au:N/C:C/I:C/A:C