CVE-2002-0760 describes a race condition in bzip2 versions prior to 1.0.2, affecting FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and potentially other operating systems. This vulnerability allows local users to temporarily read the contents of files being decompressed, as bzip2 initially creates them with world-readable permissions before applying the intended permissions from the archive. The severity is low (CVSS 1.2) due to a local attack vector and high attack complexity, with the primary impact being potential information disclosure. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.0CPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:0.9.0:*:*:*:*:*:*:* | ||
0.9.0aCPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:0.9.0a:*:*:*:*:*:*:* | ||
0.9.0bCPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:0.9.0b:*:*:*:*:*:*:* | ||
0.9.0cCPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:0.9.0c:*:*:*:*:*:*:* | ||
0.9.5aCPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:0.9.5a:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.