CVE
- Id
- 5210
- CVE No.
- CVE-2002-0820
- Status
- Candidate
- Description
- FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges.
- Phase
- Proposed (20020830)
- Votes
- ACCEPT(2) Baker, Cole | NOOP(4) Christey, Cox, Foat, Wall
- Comments
- Christey> MISC:http://www.guninski.com/freebsd2.html | Christey> Other OSes besides FreeBSD are affected. | | HP:SSRT0845U | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104800750626108&w=2 | | CERT-VN:VU#809347 | Need to more closely examine the relationship between | CVE-2002-0820 and CVE-2002-0572, especially with respect to | references.