Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:39
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-018.1.txt - Patch, Vendor Advisory | |
References | () http://mail.gnu.org/archive/html/bug-fileutils/2002-03/msg00028.html - | |
References | () http://www.iss.net/security_center/static/8432.php - Patch, Vendor Advisory | |
References | () http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-031.php - | |
References | () http://www.redhat.com/support/errata/RHSA-2003-015.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2003-016.html - | |
References | () http://www.securityfocus.com/archive/1/260936 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/4266 - Patch, Vendor Advisory |
Information
Published : 2002-07-26 04:00
Updated : 2024-11-20 23:39
NVD link : CVE-2002-0435
Mitre link : CVE-2002-0435
CVE.ORG link : CVE-2002-0435
JSON object : View
Products Affected
gnu
- fileutils
CWE