Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2007-0392
Disclosure Date: January 19, 2007 (last updated October 04, 2023)
IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.
0
Attacker Value
Unknown
CVE-2007-0394
Disclosure Date: January 19, 2007 (last updated October 04, 2023)
HP HP-UX B11.11 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.
0
Attacker Value
Unknown
CVE-2007-0393
Disclosure Date: January 19, 2007 (last updated October 04, 2023)
Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.
0
Attacker Value
Unknown
CVE-2002-0572
Disclosure Date: July 03, 2002 (last updated February 22, 2025)
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
0