VulnerabilityModified
CVE-2002-0145
chuid 1.2 and earlier does not properly verify the ownership of files that will be changed, which allows remote attackers to change files owned by other users, such as root.
HIGH 7.5EPSS 1.57%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
chuid 1.2 and earlier does not properly verify the ownership of files that will be changed, which allows remote attackers to change files owned by other users, such as root.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- scott parish/chuid
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/251763Vendor Advisory
- http://www.securityfocus.com/bid/3938
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7976
- http://online.securityfocus.com/archive/1/251763Vendor Advisory
- http://www.securityfocus.com/bid/3938
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7976
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.