CVE-2002-0129 describes a local file disclosure vulnerability in efax version 0.9 and earlier. When efax is installed with setuid root permissions, local users can read arbitrary files by leveraging the -d option, which inadvertently prints file contents within a warning message. This is a low-severity vulnerability with a CVSS score of 2.1, requiring local access and low attack complexity to achieve partial confidentiality impact. There is no evidence of active exploitation, nor are there known public exploits in Metasploit, Nuclei, or ExploitDB, although it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8aCPE matchmatch criteria | cpe:2.3:a:efax:efax:0.8a:*:*:*:*:*:*:* | ||
0.9CPE matchmatch criteria | cpe:2.3:a:efax:efax:0.9:*:*:*:*:*:*:* | ||
0.9aCPE matchmatch criteria | cpe:2.3:a:efax:efax:0.9a:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.