6.2
CVSSv2

CVE-2002-0638

Published: 12/08/2002 Updated: 18/10/2016
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 552
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and previous versions, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh.

Vulnerable Product Search on Vulmon Subscribe to Product

mandrakesoft mandrake single network firewall 7.2

mandrakesoft mandrake linux 7.2

mandrakesoft mandrake linux 8.0

redhat linux 6.0

redhat linux 7.0

redhat linux 7.1

mandrakesoft mandrake linux 8.1

redhat linux 6.1

mandrakesoft mandrake linux 7.0

mandrakesoft mandrake linux 7.1

mandrakesoft mandrake linux corporate server 1.0.1

redhat linux 6.2

redhat linux 7.2

redhat linux 7.3

hp secure os 1.0

mandrakesoft mandrake linux 8.2