CVE-2002-0638
published 2002-08-12CVE-2002-0638: setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when…
PriorityP413medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.53%
41.2th percentile
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | secure_os | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux_corporate_server | — | — |
| mandrakesoft | mandrake_single_network_firewall | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2002-07-29·CVSS 6.2
CVE-2002-0638 [MEDIUM] security flaw
security flaw
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh.
GHSA
GHSA-gmmv-6j82-fwgw: setpwnam
ghsa_unreviewed·2022-05-03
CVE-2002-0638 [MEDIUM] GHSA-gmmv-6j82-fwgw: setpwnam
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh.
No detection rules found.
No public exploits indexed.
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-043.0.txthttp://archives.neohapsis.com/archives/bugtraq/2002-07/0357.htmlhttp://archives.neohapsis.com/archives/bugtraq/2002-07/0396.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000523http://marc.info/?l=bugtraq&m=102795787713996&w=2http://online.securityfocus.com/advisories/4320http://rhn.redhat.com/errata/RHSA-2002-132.htmlhttp://www.iss.net/security_center/static/9709.phphttp://www.kb.cert.org/vuls/id/405955http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-047.phphttp://www.osvdb.org/5164http://www.redhat.com/support/errata/RHSA-2002-137.htmlhttp://www.securityfocus.com/bid/5344ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-043.0.txthttp://archives.neohapsis.com/archives/bugtraq/2002-07/0357.htmlhttp://archives.neohapsis.com/archives/bugtraq/2002-07/0396.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000523http://marc.info/?l=bugtraq&m=102795787713996&w=2http://online.securityfocus.com/advisories/4320http://rhn.redhat.com/errata/RHSA-2002-132.htmlhttp://www.iss.net/security_center/static/9709.phphttp://www.kb.cert.org/vuls/id/405955http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-047.phphttp://www.osvdb.org/5164http://www.redhat.com/support/errata/RHSA-2002-137.htmlhttp://www.securityfocus.com/bid/5344
2002-08-12
Published