VulnerabilityModified
CVE-2002-0080
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
LOW 2.1EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- samba/rsync · redhat/linux
- Source
- cve@mitre.org
References
- http://www.caldera.com/support/security/advisories/CSSA-2002-014.1.txtBroken Link
- http://www.iss.net/security_center/static/8463.phpBroken Link
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-024.php3Broken Link
- http://www.redhat.com/support/errata/RHSA-2002-026.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/4285Third Party Advisory, VDB Entry
- http://www.caldera.com/support/security/advisories/CSSA-2002-014.1.txtBroken Link
- http://www.iss.net/security_center/static/8463.phpBroken Link
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-024.php3Broken Link
- http://www.redhat.com/support/errata/RHSA-2002-026.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/4285Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.