7.2

CVE-2002-0754

Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.

Data is provided by the National Vulnerability Database (NVD)
FreebsdHeimdal Version0.4e
KthHeimdal Version0.4e
FreebsdFreebsd Version4.0
FreebsdFreebsd Version4.1
FreebsdFreebsd Version4.1.1
FreebsdFreebsd Version4.1.1 Updaterelease
FreebsdFreebsd Version4.1.1 Updatestable
FreebsdFreebsd Version4.2
FreebsdFreebsd Version4.2 Updatestable
FreebsdFreebsd Version4.3
FreebsdFreebsd Version4.3 Updaterelease
FreebsdFreebsd Version4.3 Updatestable
FreebsdFreebsd Version4.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.364
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C