CVE-2002-2382

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
31/12/2002
Last modified:
03/04/2025

Description

cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on /var/tmp/cvsupd.out.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cvsup:cvsup:1.2:*:*:*:*:*:*:*