Vulnerability Description
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Slrn Development Team | Slrn | 0.9.6.2 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0302.html
- http://online.securityfocus.com/archive/1/269667Exploit
- http://online.securityfocus.com/archive/1/270235
- http://www.iss.net/security_center/static/8910.phpVendor Advisory
- http://www.securityfocus.com/bid/4569ExploitPatchVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0302.html
- http://online.securityfocus.com/archive/1/269667Exploit
- http://online.securityfocus.com/archive/1/270235
- http://www.iss.net/security_center/static/8910.phpVendor Advisory
- http://www.securityfocus.com/bid/4569ExploitPatchVendor Advisory
FAQ
What is CVE-2002-0740?
CVE-2002-0740 is a vulnerability with a CVSS score of 7.2 (HIGH). Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument.
How severe is CVE-2002-0740?
CVE-2002-0740 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0740?
Check the references section above for vendor advisories and patch information. Affected products include: Slrn Development Team Slrn.