CVE-2002-0820
Last modified
CVE-2002-0820 is a vulnerability of currently unknown severity. FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 4.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0820?
How severe is CVE-2002-0820?
How do I fix CVE-2002-0820?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0814Buffer overflow in VMware Authorization Service for VMware G…
- CVE-2002-0815The Javascript "Same Origin Policy" (SOP), as implemented in…
- CVE-2002-0816Buffer overflow in su in Tru64 Unix 5.x allows local users t…
- CVE-2002-0817Format string vulnerability in super for Linux allows local …
- CVE-2002-0818wwwoffled in World Wide Web Offline Explorer (WWWOFFLE) allo…
- CVE-2002-0819Format string vulnerability in artsd, when called by artswra…
- CVE-2002-0821Buffer overflows in Ethereal 0.9.4 and earlier allow remote …
- CVE-2002-0822Ethereal 0.9.4 and earlier allows remote attackers to cause …
- CVE-2002-0823Buffer overflow in Winhlp32.exe allows remote attackers to e…
- CVE-2002-0824BSD pppd allows local users to change the permissions of arb…
- CVE-2002-0825Buffer overflow in the DNS SRV code for nss_ldap before nss_…
- CVE-2002-0826Buffer overflow in WS_FTP FTP Server 3.1.1 allows remote aut…
Are you affected by CVE-2002-0820?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
