Vulnerability Name: | CVE-2000-0566 (CCN-4900) | ||||||||
Assigned: | 2000-07-03 | ||||||||
Published: | 2000-07-03 | ||||||||
Updated: | 2018-05-03 | ||||||||
Summary: | makewhatis in Linux man package allows local users to overwrite files via a symlink attack. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CALDERA Type: UNKNOWN CSSA-2000-021.0 Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-2000-021.0 symlink attack on makewhatis script possible Source: CCN Type: BugTraq Mailing List, Fri Jul 07 2000 - 10:41:01 CDT [Security Announce] man update Source: BUGTRAQ Type: UNKNOWN 20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - MAN Source: CCN Type: Conectiva Linux Announcement CLSA-2000:249 man: Insecure directory creation in /tmp Source: MITRE Type: CNA CVE-2000-0566 Source: MANDRAKE Type: UNKNOWN MDKSA-2000:015 Source: CCN Type: RHSA-2000:041-02 man package's 'makewhatis' uses insecure handling of files in /tmp Source: CCN Type: Internet Security Systems Security Alert #56 Insecure temporary file handling in Linux makewhatis Source: CCN Type: US-CERT VU#35842 man `makewhatis` insecurely uses /tmp Source: CCN Type: OSVDB ID: 5714 man makewhatis Overwrite Arbitrary File Source: REDHAT Type: UNKNOWN RHSA-2000:041 Source: BID Type: UNKNOWN 1434 Source: CCN Type: BID-1434 Multiple Vendor man(1) makewhatis Insecure /tmp Files Vulnerability Source: CCN Type: MandrakeSoft Security Advisory MDKSA-2000:015 man Source: XF Type: UNKNOWN linux-man-makewhatis-tmp(4900) Source: XF Type: UNKNOWN linux-man-makewhatis-tmp(4900) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |