VYPR
Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Jun 16, 2026

CVE-2002-0424

CVE-2002-0424

Description

efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.

Affected products

3
  • Efingerd/Efingerd3 versions
    cpe:2.3:a:efingerd:efingerd:1.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:efingerd:efingerd:1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:efingerd:efingerd:1.6.1:*:*:*:*:*:*:*
    • (no CPE)range: <=1.61

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.