CVE-2002-0080Improper Privilege Management in Samba Rsync

Severity
2.1LOWNVD
EPSS
0.8%
top 26.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 15
Latest updateApr 30

Description

rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

NVDsamba/rsync< 2.5.3
NVDredhat/linux4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mghq-fcpm-9vvg: rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to2022-04-30
CVEList
CVE-2002-0080: rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to2002-06-25

📋Vendor Advisories

2
Cisco
Vulnerability in the zlib Compression Library2002-04-03
Red Hat
security flaw2002-03-11

💬Community

1
Bugzilla
CVE-2002-0080 security flaw2018-08-16
CVE-2002-0080 — Improper Privilege Management in Samba | cvebase