Vulnerability Name: | CVE-2001-1331 (CCN-9989) | ||||||||||||
Assigned: | 2001-05-03 | ||||||||||||
Published: | 2001-05-03 | ||||||||||||
Updated: | 2008-09-10 | ||||||||||||
Summary: | mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks. | ||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||||||
CVSS v2 Severity: | 1.2 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2001-1331 Source: CCN Type: Progeny Service Network Security Advisory PROGENY-SA-2001-12 mandb handles temporary databases insecurely Source: CONFIRM Type: UNKNOWN http://online.securityfocus.com/advisories/3307 Source: DEBIAN Type: Patch, Vendor Advisory DSA-056 Source: DEBIAN Type: DSA-056 man-db -- local file overwrite Source: DEBIAN Type: DSA-059 man-db -- symlink attack Source: CCN Type: OSVDB ID: 11795 man-db mandb Command Line Option Arbitrary File Overwrite Source: BID Type: UNKNOWN 2720 Source: CCN Type: BID-2720 Debian man-db Executable Overwrite Vulnerability Source: XF Type: UNKNOWN mandb-tmpfile-symlink(9989) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |