CVE-2002-0424

efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.

Scoring

CVSS base score
0
EPSS probability
0.07%
Published
2003-04-02
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs