PT-2002-3046 · Joe · Joe
Publicado
2002-12-31
·
Atualizado
2008-09-05
·
CVE-2002-2334
CVSS v2.0
3.6
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Joe text editor versions 2.8 through 2.9.7
Description
The issue allows local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users, due to the failure to remove the group and user setuid bits for backup files.
Recommendations
For Joe text editor versions 2.8 through 2.9.7, consider removing the setuid and setgid bits from backup files manually to prevent exploitation until a proper fix is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Joe