VYPR
Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Apr 16, 2026

CVE-2002-0424

CVE-2002-0424

Description

efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.

Affected products

3
  • Efingerd/Efingerd3 versions
    cpe:2.3:a:efingerd:efingerd:1.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:efingerd:efingerd:1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:efingerd:efingerd:1.6.1:*:*:*:*:*:*:*
    • (no CPE)range: <=1.61

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.