Lucene search

K
cveMitreCVE-2002-0761
HistoryApr 02, 2003 - 5:00 a.m.

CVE-2002-0761

2003-04-0205:00:00
mitre
web.nvd.nist.gov
28
cve-2002-0761
bzip2
freebsd
openlinux
permissions
archive vulnerability

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

20.0%

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an archive, which could cause the files to be extracted with less restrictive permissions than intended.

Affected configurations

Nvd
Node
bzipbzip2Match0.9.0
OR
bzipbzip2Match0.9.0a
OR
bzipbzip2Match0.9.0b
OR
bzipbzip2Match0.9.0c
OR
bzipbzip2Match0.9.5a
OR
bzipbzip2Match0.9.5b
OR
bzipbzip2Match0.9.5c
OR
bzipbzip2Match0.9.5d
OR
bzipbzip2Match1.0
OR
bzipbzip2Match1.0.1
VendorProductVersionCPE
bzipbzip20.9.0cpe:2.3:a:bzip:bzip2:0.9.0:*:*:*:*:*:*:*
bzipbzip20.9.0acpe:2.3:a:bzip:bzip2:0.9.0a:*:*:*:*:*:*:*
bzipbzip20.9.0bcpe:2.3:a:bzip:bzip2:0.9.0b:*:*:*:*:*:*:*
bzipbzip20.9.0ccpe:2.3:a:bzip:bzip2:0.9.0c:*:*:*:*:*:*:*
bzipbzip20.9.5acpe:2.3:a:bzip:bzip2:0.9.5a:*:*:*:*:*:*:*
bzipbzip20.9.5bcpe:2.3:a:bzip:bzip2:0.9.5b:*:*:*:*:*:*:*
bzipbzip20.9.5ccpe:2.3:a:bzip:bzip2:0.9.5c:*:*:*:*:*:*:*
bzipbzip20.9.5dcpe:2.3:a:bzip:bzip2:0.9.5d:*:*:*:*:*:*:*
bzipbzip21.0cpe:2.3:a:bzip:bzip2:1.0:*:*:*:*:*:*:*
bzipbzip21.0.1cpe:2.3:a:bzip:bzip2:1.0.1:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

20.0%

Related for CVE-2002-0761