CHUID Privileged File Owner Changing Vulnerability

BID:3938

Info

CHUID Privileged File Owner Changing Vulnerability

Bugtraq ID: 3938
Class: Access Validation Error
CVE: CVE-2002-0145
Remote: Yes
Local: No
Published: Jan 21 2002 12:00AM
Updated: Jul 11 2009 09:56AM
Credit: This vulnerability was announced by Scott Parish <[email protected]> via Bugtraq on January 21, 2002.
Vulnerable: chuid chuid 1.2
- Apache Apache 1.3.22
- Apache Apache 1.3.20
- Apache Apache 1.3.19
chuid chuid 1.1
- Apache Apache 1.3.22
- Apache Apache 1.3.20
- Apache Apache 1.3.19
chuid chuid 1.0
- Apache Apache 1.3.22
- Apache Apache 1.3.20
- Apache Apache 1.3.19
Not Vulnerable: chuid chuid 1.3
- Apache Apache 1.3.22
- Apache Apache 1.3.20
- Apache Apache 1.3.19

Discussion

CHUID Privileged File Owner Changing Vulnerability

chuid is a freely available, open source user id changing utility. It was written and is maintained by Scott Parish. It is designed for use on the Linux operating system.

chuid does not properly handle user-supplied input. Due to insufficient checking of user input, it is possible for a remote user to change the ownership of a file owned by a privileged user. This could allow a remote user to change the ownership or group membership of a restricted or privileged file.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report