Improper Privilege Management in Rsync - CVE-2002-0080
Published: January 30, 2024
Vulnerability identifier: #VU85903
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2002-0080
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to rsync, when running in daemon mode, does not properly call setgroups before dropping privileges. A local user can get supplemental group privileges to read certain files that would otherwise be disallowed.
Affected software
Rsync
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2002-0080
Install updates from vendor's website.
Rsync - update to 2.5.3
Cloud Pak for Network Automation - update to 2.6.5
IBM Cloud Pak for Watson AIOps - update to 4.2.0
Cloud Pak for Network Automation - update to 2.6.5
IBM Cloud Pak for Watson AIOps - update to 4.2.0