CVE-2002-0080
published 2002-03-15CVE-2002-0080: rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local…
PriorityP49low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.52%
40.8th percentile
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| samba | rsync | < 2.5.3 | 2.5.3 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Vulnerability in the zlib Compression Library
vendor_cisco·2002-04-03
CVE-2002-0059 Vulnerability in the zlib Compression Library
Vulnerability in the zlib Compression Library
There is a vulnerability in the zlib compression library. This code is
used in multiple applications. While we have not identified any Cisco product
that is directly impacted by the vulnerability, there are several products that
are using third-party modules that are vulnerable or that are running on an
operating system that is vulnerable. This vulnerability has been publicly
disclosed.
Cisco PSIRT is still evaluating which products are affected by this
vulnerability.
There is no workaround for this vulnerability.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020403-zlib-double-free.
Red Hat
security flaw
vendor_redhat·2002-03-11·CVSS 2.1
CVE-2002-0080 [LOW] security flaw
security flaw
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
Cisco
Vulnerability in the zlib Compression Library
vendor_cisco
CVE-2002-0080 Vulnerability in the zlib Compression Library
CVE-2002-0080: Vulnerability in the zlib Compression Library
There is a vulnerability in the zlib compression library. This code is used in multiple applications. While we have not identified any Cisco product that is directly impacted by the vulnerability, there are several products that are using third-party modules that are vulnerable or that are running on an operating system that is vulnerable. This vulnerability has been publicly disclosed. Cisco PSIRT is still evaluating which products are affected by this vulnerability. There is no workaround for this vulnerability. This advisory is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020403-zlib-double-free .
GHSA
GHSA-mghq-fcpm-9vvg: rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to
ghsa_unreviewed·2022-04-30
CVE-2002-0080 [LOW] CWE-269 GHSA-mghq-fcpm-9vvg: rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
No detection rules found.
No public exploits indexed.
CWE
Placement of User into Incorrect Group
mitre_cwe·CVSS 10.0
[CRITICAL] CWE-842 Placement of User into Incorrect Group
CWE-842: Placement of User into Incorrect Group
The product or the administrator places a user into an incorrect group.
If the incorrect group has more access or privileges than the intended group, the user might be able to bypass intended security policy to access unexpected resources or perform unexpected actions. The access-control system might not be able to detect malicious usage of this group membership.
Modes of Introduction:
Phase: Implementation
Phase: Operation
Common Consequences:
Scope: Access Control. Impact: Gain Privileges or Assume Identity.
Observed Examples:
CVE-1999-1193: Operating system assigns user to privileged wheel group, allowing the user to gain root privileges.
CVE-2010-3716: Chain: drafted web request allows the creation of users with arbitrary group membe
CWE
Privilege Dropping / Lowering Errors
mitre_cwe
CWE-271 Privilege Dropping / Lowering Errors
CWE-271: Privilege Dropping / Lowering Errors
The product does not drop privileges before passing control of a resource to an actor that does not have those privileges.
In some contexts, a system executing with elevated permissions will hand off a process/file/etc. to another process or user. If the privileges of an entity are not reduced, then elevated privileges are spread throughout a system and possibly to an attacker.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Phase: Operation
Common Consequences:
Scope: Access Control. Impact: Gain Privileges or Assume Identity. If privileges are not dropped, neither are access rights of the user. Often these righ
http://www.caldera.com/support/security/advisories/CSSA-2002-014.1.txthttp://www.iss.net/security_center/static/8463.phphttp://www.linux-mandrake.com/en/security/2002/MDKSA-2002-024.php3http://www.redhat.com/support/errata/RHSA-2002-026.htmlhttp://www.securityfocus.com/bid/4285http://www.caldera.com/support/security/advisories/CSSA-2002-014.1.txthttp://www.iss.net/security_center/static/8463.phphttp://www.linux-mandrake.com/en/security/2002/MDKSA-2002-024.php3http://www.redhat.com/support/errata/RHSA-2002-026.htmlhttp://www.securityfocus.com/bid/4285
2002-03-15
Published