CVE-2002-0435
Summary
| CVE | CVE-2002-0435 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-07-26 04:00:00 UTC |
| Updated | 2008-09-05 20:28:00 UTC |
| Description | Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Fileutils | 4.0 | All | All | All |
| Application | Gnu | Fileutils | 4.1 | All | All | All |
| Application | Gnu | Fileutils | 4.1.6 | All | All | All |
| Application | Gnu | Fileutils | 4.0 | All | All | All |
| Application | Gnu | Fileutils | 4.1 | All | All | All |
| Application | Gnu | Fileutils | 4.1.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GNU Fileutils Directory Removal Race Condition Vulnerability | BID | www.securityfocus.com | Patch, Vendor Advisory |
| CSSA-2002-018.1 | CALDERA | ftp.caldera.com | Patch, Vendor Advisory |
| Re: rm - recursive directory removal race condition | CONFIRM | mail.gnu.org | |
| redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| MDKSA-2002:031 | MANDRAKE | www.linux-mandrake.com | |
| ISS X-Force Database: gnu-fileutils-race-condition (8432): GNU fileutils race condition | XF | www.iss.net | Patch, Vendor Advisory |
| SecurityFocus HOME Mailing List: BugTraq | BUGTRAQ | www.securityfocus.com | Vendor Advisory |
| redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.