CVE-2002-0761 describes a vulnerability in bzip2 versions prior to 1.0.2, affecting FreeBSD 4.5 and earlier, and OpenLinux 3.1 and 3.1.1. This flaw allows bzip2 to incorrectly apply the permissions of symbolic links to the actual files during archive creation, potentially leading to files being extracted with less restrictive permissions than intended. The vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating a local attack vector with low complexity, and a potential impact of partial confidentiality loss. Its FAUCET Risk Score is 5/100, and its EPSS score is very low, suggesting minimal exploitability in the wild. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered no community discussion or media coverage, indicating a lack of widespread attention or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.0CPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:0.9.0:*:*:*:*:*:*:* | ||
0.9.0aCPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:0.9.0a:*:*:*:*:*:*:* | ||
0.9.0bCPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:0.9.0b:*:*:*:*:*:*:* | ||
0.9.0cCPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:0.9.0c:*:*:*:*:*:*:* | ||
0.9.5aCPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:0.9.5a:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.