Vulnerability Name:

CVE-2002-0875 (CCN-9880)

Assigned:2002-08-15
Published:2002-08-15
Updated:2008-09-10
Summary:Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: CCN
Type: FreeBSD Security Notice FreeBSD-SN-02:05
security issues in ports

Source: FREEBSD
Type: UNKNOWN
FreeBSD-SN-02:05

Source: SGI
Type: UNKNOWN
20000301-03-I

Source: CCN
Type: Debian Bug Report Logs - #148853
fam doesn't work

Source: MITRE
Type: CNA
CVE-2002-0875

Source: CCN
Type: SGI Bugzilla Bug 151
flaw in primary group handling - unable to FAM files in some directories

Source: CCN
Type: RHSA-2005-005
fam security update

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-154

Source: DEBIAN
Type: DSA-154
fam -- privilege escalation

Source: XF
Type: UNKNOWN
sgi-fam-insecure-permissions(9880)

Source: REDHAT
Type: UNKNOWN
RHSA-2005:005

Source: BID
Type: UNKNOWN
5487

Source: CCN
Type: BID-5487
SGI FAM Arbitrary Root Owned Directory File Listing Vulnerability

Source: XF
Type: UNKNOWN
sgi-fam-insecure-permissions(9880)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sgi:fam:2.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:fam:2.6.8:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.15:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.16:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.17:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:freebsd:ports_collection:*:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:*
  • OR cpe:/o:redhat:linux_advanced_workstation:2.1:*:itanium:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20020875
    V
    CVE-2002-0875
    2015-11-16
    oval:org.debian:def:154
    V
    privilege escalation
    2002-08-15
    BACK
    sgi fam 2.6.6
    sgi fam 2.6.8
    sgi irix 6.5.15
    sgi irix 6.5.16
    sgi irix 6.5.17
    debian debian linux 3.0
    freebsd ports collection *
    debian debian linux 3.0
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat linux advanced workstation 2.1