7.2
CVSSv2

CVE-2002-0542

Published: 03/07/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openbsd 3.0

openbsd openbsd 2.9

Exploits

/* source: wwwsecurityfocuscom/bid/4495/info OpenBSD ships with a number of cron jobs configured by default The tasks are for the purpose of summarizing system information The mail(1) utility is used to send the summaries to the root user This utility supports escaped characters in message text indicating commands to be executed durin ...