Vulnerability Name:

CVE-2002-0080 (CCN-8463)

Assigned:2002-03-13
Published:2002-03-13
Updated:2020-11-16
Summary:rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-269
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: Caldera International, Inc. Security Advisory CSSA-2002-014.1
Linux: REVISED: rsync supplementary groups vulnerability

Source: CCN
Type: Caldera International, Inc. Security Advisory CSSA-2002-014.0
Linux: rsync supplementary groups vulnerability

Source: MITRE
Type: CNA
CVE-2002-0080

Source: CCN
Type: RHSA-2002-026
Vulnerability in zlib library

Source: CALDERA
Type: Broken Link
CSSA-2002-014.1

Source: XF
Type: Broken Link
linux-rsync-inherit-privileges(8463)

Source: MANDRAKE
Type: Broken Link
MDKSA-2002:024

Source: CCN
Type: OSVDB ID: 2053
rsync Daemon Mode Supplementary Group Privilege

Source: REDHAT
Type: Patch, Third Party Advisory
RHSA-2002:026

Source: BID
Type: Third Party Advisory, VDB Entry
4285

Source: CCN
Type: BID-4285
RSync Daemon Mode Supplementary Group Privilege Vulnerability

Source: XF
Type: UNKNOWN
linux-rsync-inherit-privileges(8463)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:samba:rsync:*:*:*:*:*:*:*:* (Version < 2.5.3)

  • Configuration 2:
  • cpe:/o:redhat:linux:6.2:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:redhat:linux:6.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:mandrakesoft:mandrake_single_network_firewall:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    samba rsync *
    redhat linux 6.2
    redhat linux 7.0
    redhat linux 7.1
    redhat linux 7.2
    redhat linux 6.2
    mandrakesoft mandrake linux 7.1
    redhat linux 7
    mandrakesoft mandrake linux 7.2
    mandrakesoft mandrake linux corporate server 1.0.1
    redhat linux 7.1
    mandrakesoft mandrake linux 8.0
    mandrakesoft mandrake single network firewall 7.2
    mandrakesoft mandrake linux 8.1
    redhat linux 7.2