← Back

CVE-2002-0080

nvd nist
Published: Mar 15, 2002Modified: Apr 16, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.

Affected (5)

Products: Samba: Rsync · Redhat: Linux
1 product
Rsync
1 product
Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.5.3
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.2
Version 7.0
Version 7.1
Version 7.2

References (10)

Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.