CVE-2002-0435
published 2002-07-26CVE-2002-0435: Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete…
PriorityP48low1.2CVSS 2.0
AVLACHAuNCNIPAN
EPSS
0.34%
26.0th percentile
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | fileutils | — | — |
| gnu | fileutils | — | — |
| gnu | fileutils | — | — |
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | sunos | — | — |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:N/I:P/A:N
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m4m8-rghq-9wjc: Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4
ghsa_unreviewed·2022-05-03
CVE-2002-0435 [LOW] GHSA-m4m8-rghq-9wjc: Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.
GHSA
GHSA-3g37-x67f-m9rp: Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to de
ghsa_unreviewed·2022-05-01·CVSS 1.2
CVE-2007-0895 [LOW] GHSA-3g37-x67f-m9rp: Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to de
Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.
Red Hat
security flaw
vendor_redhat·2002-03-07·CVSS 1.2
CVE-2002-0435 [LOW] security flaw
security flaw
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.
No detection rules found.
No public exploits indexed.
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-018.1.txthttp://mail.gnu.org/archive/html/bug-fileutils/2002-03/msg00028.htmlhttp://www.iss.net/security_center/static/8432.phphttp://www.linux-mandrake.com/en/security/2002/MDKSA-2002-031.phphttp://www.redhat.com/support/errata/RHSA-2003-015.htmlhttp://www.redhat.com/support/errata/RHSA-2003-016.htmlhttp://www.securityfocus.com/archive/1/260936http://www.securityfocus.com/bid/4266ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-018.1.txthttp://mail.gnu.org/archive/html/bug-fileutils/2002-03/msg00028.htmlhttp://www.iss.net/security_center/static/8432.phphttp://www.linux-mandrake.com/en/security/2002/MDKSA-2002-031.phphttp://www.redhat.com/support/errata/RHSA-2003-015.htmlhttp://www.redhat.com/support/errata/RHSA-2003-016.htmlhttp://www.securityfocus.com/archive/1/260936http://www.securityfocus.com/bid/4266
2002-07-26
Published