CVE DATABASE / CVE-2002-0542
CVE-2002-0542
CVSS 7.2 · HIGH
Summary
mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.
CVSS 2.0 breakdown
| Base score | 7.2 (HIGH) |
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| Attack vector | LOCAL |
| Attack complexity | LOW |
| Confidentiality | COMPLETE |
| Integrity | COMPLETE |
| Availability | COMPLETE |
Affected products
Openbsd openbsd
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://marc.info/?l=bugtraq&m=101855467811695&w=2
- http://online.securityfocus.com/archive/1/267089
- http://www.iss.net/security_center/static/8818.php
- http://www.openbsd.org/errata30.html#mail
- http://www.osvdb.org/5269
- http://www.securityfocus.com/bid/4495
Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.