Improper Privilege Management in Rsync - CVE-2002-0080

 

Improper Privilege Management in Rsync - CVE-2002-0080

Published: January 30, 2024


Vulnerability identifier: #VU85903
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2002-0080
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to rsync, when running in daemon mode, does not properly call setgroups before dropping privileges. A local user can get supplemental group privileges to read certain files that would otherwise be disallowed.


Affected software

Rsync
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2002-0080

Install updates from vendor's website.

Rsync - update to 2.5.3
Cloud Pak for Network Automation - update to 2.6.5
IBM Cloud Pak for Watson AIOps - update to 4.2.0

External References

Related Security Bulletins