Vulnerability Name: | CVE-2001-0125 (CCN-5829) | ||||||||
Assigned: | 2000-12-31 | ||||||||
Published: | 2000-12-31 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 1.2 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-01:17 exmh symlink vulnerability Source: CCN Type: BugTraq Mailing List, Sun Dec 31 2000 - 14:32:40 CST Advisory: exmh symlink vulnerability Source: FREEBSD Type: UNKNOWN FreeBSD-SA-01:17 Source: MITRE Type: CNA CVE-2001-0125 Source: BUGTRAQ Type: UNKNOWN 20001231 Advisory: exmh symlink vulnerability Source: BUGTRAQ Type: UNKNOWN 20010112 exmh security vulnerability Source: CCN Type: Beedub Web site Exmh symlink attack Source: CONFIRM Type: Patch, Vendor Advisory http://www.beedub.com/exmh/symlink.html Source: DEBIAN Type: UNKNOWN DSA-022 Source: DEBIAN Type: DSA-022 exmh -- local insecure tempfile creation Source: MANDRAKE Type: Patch MDKSA-2001:015 Source: CCN Type: OSVDB ID: 7163 exmh exmhErrorMsg Symlink Overwrite Arbitrary File Source: CCN Type: BID-2201 Exmh Local Symlink Vulnerability Source: CCN Type: MandrakeSoft Security Advisory MDKSA-2001:015 exmh update Source: XF Type: UNKNOWN exmh-error-symlink(5829) Source: XF Type: UNKNOWN exmh-error-symlink(5829) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |