PT-2002-1026 · Gnu · At
Published
2002-01-15
·
Updated
2017-10-10
·
CVE-2002-0004
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
at versions prior to the fixed version
Description
The issue is related to a heap corruption vulnerability in the "at" program, allowing local users to execute arbitrary code via a malformed execution time. This vulnerability can cause the "at" program to free the same memory twice, leading to potential security issues. Additionally, multiple vulnerabilities in the "at" package may lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited by a local attacker.
Recommendations
For at versions prior to the fixed version, update to the latest version to resolve the issue.
As a temporary workaround, consider restricting access to the "at" program to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
At