Vulnerabilities > CVE-2002-0572
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 3 | |
OS | 4 | |
OS | 8 |
Exploit-Db
description | OS X 10.x, FreeBSD 4.x,OpenBSD 2.x,Solaris 2.5/2.6/7.0/8 exec C Library Standard I/O File Descriptor Closure. CVE-2002-0572. Local exploit for bsd platform |
id | EDB-ID:21407 |
last seen | 2016-02-02 |
modified | 2002-04-23 |
published | 2002-04-23 |
reporter | phased |
source | https://www.exploit-db.com/download/21407/ |
title | OS X 10.x, FreeBSD 4.x,OpenBSD 2.x,Solaris 2.5/2.6/7.0/8 exec C Library Standard I/O File Descriptor Closure |
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:23.stdio.asc
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0033.html
- http://online.securityfocus.com/archive/1/268970
- http://online.securityfocus.com/archive/1/269102
- http://www.ciac.org/ciac/bulletins/m-072.shtml
- http://www.iss.net/security_center/static/8920.php
- http://www.kb.cert.org/vuls/id/809347
- http://www.osvdb.org/6095
- http://www.securityfocus.com/bid/4568