LOW · 2.1

CVE-2002-0080

rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files tha...

Vulnerability Description

rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SambaRsync< 2.5.3
RedhatLinux6.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2002-0080?

CVE-2002-0080 is a vulnerability with a CVSS score of 2.1 (LOW). rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files tha...

How severe is CVE-2002-0080?

CVE-2002-0080 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0080?

Check the references section above for vendor advisories and patch information. Affected products include: Samba Rsync, Redhat Linux.