CVE-2002-0080
Summary
| CVE | CVE-2002-0080 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-03-15 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RSync Daemon Mode Supplementary Group Privilege Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Patch, Third Party Advisory |
| 404 | Caldera | af854a3a-2127-422b-91ae-364da2661108 | www.caldera.com | Broken Link |
| ISS X-Force Database: linux-rsync-inherit-privileges (8463): Linux rsync fails to drop privileges for supplementary groups in daemon mode | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Broken Link |
| www.linux-mandrake.com/en/security/2002/MDKSA-2002-024.php3 | af854a3a-2127-422b-91ae-364da2661108 | www.linux-mandrake.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 900285 CBL-Mariner Linux Security Update for rsync 3.1.3