CVE-2002-2334

Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:joseph_allen:joe:2.8:*:*:*:*:*:*:*
cpe:2.3:a:joseph_allen:joe:2.9:*:*:*:*:*:*:*
cpe:2.3:a:joseph_allen:joe:2.9.1:*:*:*:*:*:*:*
cpe:2.3:a:joseph_allen:joe:2.9.2:*:*:*:*:*:*:*
cpe:2.3:a:joseph_allen:joe:2.9.4:*:*:*:*:*:*:*
cpe:2.3:a:joseph_allen:joe:2.9.5:*:*:*:*:*:*:*
cpe:2.3:a:joseph_allen:joe:2.9.6:*:*:*:*:*:*:*
cpe:2.3:a:joseph_allen:joe:2.9.7:*:*:*:*:*:*:*

History

20 Nov 2024, 23:43

Type Values Removed Values Added
References () http://online.securityfocus.com/archive/1/292138 - () http://online.securityfocus.com/archive/1/292138 -
References () http://www.iss.net/security_center/static/10125.php - () http://www.iss.net/security_center/static/10125.php -
References () http://www.securityfocus.com/bid/5732 - () http://www.securityfocus.com/bid/5732 -

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:43


NVD link : CVE-2002-2334

Mitre link : CVE-2002-2334

CVE.ORG link : CVE-2002-2334


JSON object : View

Products Affected

joseph_allen

  • joe
CWE
CWE-264

Permissions, Privileges, and Access Controls