PT-2002-2744 · Beep2 · Beep2

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2023

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions beep2 versions 1.0 through 1.2
Description The issue concerns the get parameter from freqency source function, which allows local users to read arbitrary files when beep2 is installed setuid root. The exact attack vectors are not specified.
Recommendations For versions 1.0 through 1.2, consider removing the setuid root installation to prevent exploitation until a patch is available. As a temporary workaround, restrict access to the get parameter from freqency source function to minimize the risk of arbitrary file reading.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2023

Affected Products

Beep2