Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2002-0004

6 documents6 sources
Severity
7.2HIGH
EPSS
0.3%
top 49.11%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedFeb 27
Latest updateApr 30

Description

Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages6 packages

NVDredhat/linux4 versions+3
NVDsuse/suse_linux5 versions+4
NVDslackware/slackware_linux7.0, 7.1, 8.0+2

Also affects: Freebsd 4.1.1, 4.2, 4.3, 4.4, Netbsd 1.5.2, Debian Linux 2.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hv62-hp8h-9vjg: Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free2022-04-30
CVEList
CVE-2002-0004: Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free2002-06-25

💥Exploits & PoCs

1
Exploit-DB
AT 3.1.8 - Formatted Time Heap Overflow2002-01-16

📋Vendor Advisories

1
Red Hat
security flaw2002-01-17

💬Community

1
Bugzilla
CVE-2002-0004 security flaw2018-08-16