PT-2002-3046 · Joe · Joe
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2334
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Joe text editor versions 2.8 through 2.9.7
Description
The issue allows local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users, due to the failure to remove the group and user setuid bits for backup files.
Recommendations
For Joe text editor versions 2.8 through 2.9.7, consider removing the setuid and setgid bits from backup files manually to prevent exploitation until a proper fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joe