CVE-2002-0557
Last modified
CVE-2002-0557 is a vulnerability of currently unknown severity. Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to auth_approval().. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to auth_approval().
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openbsd | 3.0 |
References
- http://www.iss.net/security_center/static/8625.phpPatch, Vendor Advisory
- http://www.securityfocus.com/bid/4338Patch, Vendor Advisory
- http://www.iss.net/security_center/static/8625.phpPatch, Vendor Advisory
- http://www.securityfocus.com/bid/4338Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0557?
How severe is CVE-2002-0557?
How do I fix CVE-2002-0557?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0551Cross-site scripting vulnerability in Dynamic Guestbook 3.0 …
- CVE-2002-0552Multiple buffer overflows in Melange Chat server 2.02 allow …
- CVE-2002-0553Cross-site scripting vulnerability in SunShop 2.5 and earlie…
- CVE-2002-0554webdriver in IBM Informix Web DataBlade 4.12 allows remote a…
- CVE-2002-0555IBM Informix Web DataBlade 4.12 unescapes user input even if…
- CVE-2002-0556Directory traversal vulnerability in Quik-Serv HTTP server 1…
- CVE-2002-0558Directory traversal vulnerability in TYPSoft FTP server 0.97…
- CVE-2002-0559Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i App…
- CVE-2002-0560PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.…
- CVE-2002-0561The default configuration of the PL/SQL Gateway web administ…
- CVE-2002-0562The default configuration of Oracle 9i Application Server 1.…
- CVE-2002-0563The default configuration of Oracle 9i Application Server 1.…
Are you affected by CVE-2002-0557?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
