VDB
CVE-2002-0435
CVE-2002-0435
PUBLISHED
CVSS 1.2000000476837158 LOW
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.
EPSS 0.34% · 26.4th percentile
Risk Scores
CVSS 2.0
1.2000000476837158
EPSS Score
0.34%
26.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| gnu | fileutils | 4.1, 4.0, 4.1.6 |
Timeline
- Jul 26, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- MDKSA-2002:031 vendor-advisory
- RHSA-2003:016 vendor-advisory
- http://mail.gnu.org/archive/html/bug-fileutils/2002-03/msg00028.html url
- RHSA-2003:015 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2002-0435 advisory
- http://www.securityfocus.com/bid/4266 url
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-018.1.txt patch
- http://www.iss.net/security_center/static/8432.php patch
- http://www.securityfocus.com/archive/1/260936 advisory