PT-2002-1026 · Gnu · At

Published

2002-01-15

·

Updated

2017-10-10

·

CVE-2002-0004

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions at versions prior to the fixed version
Description The issue is related to a heap corruption vulnerability in the "at" program, allowing local users to execute arbitrary code via a malformed execution time. This vulnerability can cause the "at" program to free the same memory twice, leading to potential security issues. Additionally, multiple vulnerabilities in the "at" package may lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited by a local attacker.
Recommendations For at versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the "at" program to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-04100
BDU:2015-07787
CVE-2002-0004

Affected Products

At