Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-10-26T19:00:00Z

Updated: 2024-09-16T17:53:53.207Z

Reserved: 2007-10-26T00:00:00Z

Link: CVE-2002-2334

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2002-12-31T05:00:00.000

Modified: 2008-09-05T20:32:57.240

Link: CVE-2002-2334

cve-icon Redhat

No data.