CVE Vulnerabilities

CVE-2000-1134

Published: Jan 09, 2001 | Modified: Oct 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing « redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

Affected Software

Name Vendor Start Version End Version
Immunix Immunix 6.2 6.2
Linux Conectiva 4.0 4.0
Linux Conectiva 4.0es 4.0es
Linux Conectiva 4.1 4.1
Linux Conectiva 4.2 4.2
Linux Conectiva 5.0 5.0
Linux Conectiva 5.1 5.1

References