CVE-2002-0178

5 documents5 sources
Severity
7.2HIGH
EPSS
0.1%
top 67.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 29
Latest updateMay 3

Description

uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

NVDgnu/sharutils4.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wwhg-qw2q-mpr3: uudecode, as available in the sharutils package before 42022-05-03
CVEList
CVE-2002-0178: uudecode, as available in the sharutils package before 42003-04-02

📋Vendor Advisories

1
Red Hat
security flaw2002-04-12

💬Community

1
Bugzilla
CVE-2002-0178 security flaw2018-08-16
CVE-2002-0178 (HIGH CVSS 7.2) | cvebase.io