Vulnerability Name:

CVE-2002-0824 (CCN-9738)

Assigned:2002-07-29
Published:2002-07-29
Updated:2021-03-11
Summary:BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.
CVSS v3 Severity:2.9 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
1.2 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-59
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: FreeBSD Security Advisory FreeBSD-SA-02:32.pppd
exploitable race condition in pppd

Source: NETBSD
Type: Broken Link
NetBSD-SA2002-010

Source: CCN
Type: Full-Disclosure Mailing List, Mon Sep 16 2002 - 21:12:48 CDT
symlink race in pppd

Source: MITRE
Type: CNA
CVE-2002-0824

Source: FREEBSD
Type: Issue Tracking, Mailing List, Third Party Advisory
FreeBSD-SA-02:32.pppd

Source: XF
Type: Broken Link
pppd-race-condition(9738)

Source: OPENBSD
Type: Third Party Advisory
20020729 011: SECURITY FIX: July 29, 2002

Source: CCN
Type: OSVDB ID: 20753
Multiple BSD pppd Race Condition Arbitrary File Permission Modification

Source: CCN
Type: OSVDB ID: 9335
Open UNIX/UnixWare ppptalk Local Privilege Escalation

Source: CCN
Type: OSVDB ID: 9336
Open UNIX/UnixWare ppp Local Privilege Escalation

Source: BID
Type: Third Party Advisory, VDB Entry
5355

Source: CCN
Type: BID-5355
Multiple Vendor BSD pppd Arbitrary File Permission Modification Race Condition Vulnerability

Source: XF
Type: UNKNOWN
pppd-race-condition(9738)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:freebsd:point-to-point_protocol_daemon:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:netbsd:netbsd:1.4.1:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.4.2:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.4:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.1:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.2:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.3:-:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.4.3:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.4:-:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5.2:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:3.1:*:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.5:-:*:*:*:*:*:*
  • OR cpe:/o:freebsd:freebsd:4.6:-:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.6:beta:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:current:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    freebsd point-to-point protocol daemon -
    netbsd netbsd 1.4.1
    freebsd freebsd 4.0
    netbsd netbsd 1.4.2
    netbsd netbsd 1.4
    freebsd freebsd 4.1
    netbsd netbsd 1.5
    freebsd freebsd 4.2
    freebsd freebsd 4.3 -
    netbsd netbsd 1.4.3
    netbsd netbsd 1.5.1
    openbsd openbsd 3.0
    freebsd freebsd 4.4 -
    netbsd netbsd 1.5.2
    openbsd openbsd 3.1
    freebsd freebsd 4.5 -
    freebsd freebsd 4.6 -
    netbsd netbsd 1.6 beta
    netbsd netbsd 1.5.3
    netbsd netbsd current