6.9
CVSSv2

CVE-2002-0824

Published: 12/08/2002 Updated: 11/03/2021
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd point-to-point protocol daemon -

Exploits

source: wwwsecurityfocuscom/bid/5355/info A vulnerability has been reported in some versions of the pppd daemon included with multiple BSD distributions A race condition error in the code may result in the pppd process changing the file permissions on an arbitrary system file pppd will generally run as a privileged user This issue ha ...