PT-2002-1478 · Effingerd · Effingerd

Publicado

2002-08-12

·

Atualizado

2008-09-05

·

CVE-2002-0424

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions efingerd versions 1.61 and earlier
Description The issue allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger, when efingerd is configured without the -u option. This is because, in such configurations, efingerd executes .efingerd files as the efingerd user, typically "nobody".
Recommendations For efingerd versions 1.61 and earlier, consider running efingerd with the -u option to prevent the execution of .efingerd files as the efingerd user. As a temporary workaround, restrict access to the .efingerd files to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0424

Produtos afetados

Effingerd