Vulnerability Name: | CVE-2001-1494 (CCN-7718) | ||||||||||||
Assigned: | 2001-12-12 | ||||||||||||
Published: | 2001-12-12 | ||||||||||||
Updated: | 2017-10-11 | ||||||||||||
Summary: | script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command. | ||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||
References: | Source: CCN Type: Linux Kernel Archives FTP site /pub/linux/utils/util-linux/ Source: CCN Type: BugTraq Mailing List, Wed Dec 12 2001 - 17:22:43 CST Silly 'script' hardlink bug Source: MITRE Type: CNA CVE-2001-1494 Source: CCN Type: RHSA-2005-782 util-linux and mount security update Source: BUGTRAQ Type: UNKNOWN 20011213 Silly 'script' hardlink bug - fixed Source: BUGTRAQ Type: UNKNOWN 20011212 Silly 'script' hardlink bug Source: CCN Type: SA16785 util-linux umount "-r" Re-Mounting Security Issue Source: SECUNIA Type: UNKNOWN 16785 Source: CCN Type: SA18502 Avaya Products util-linux / mount Security Issue and Vulnerability Source: SECUNIA Type: UNKNOWN 18502 Source: MISC Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2006-014.htm Source: CCN Type: ASA-2006-014 util-linux and mount security update (RHSA-2005-782) Source: REDHAT Type: Vendor Advisory RHSA-2005:782 Source: BID Type: UNKNOWN 16280 Source: CCN Type: BID-16280 Util-Linux Script Command Arbitrary File Overwrite Vulnerability Source: XF Type: UNKNOWN util-linux-script-hardlink(7718) Source: XF Type: UNKNOWN util-linux-script-hardlink(7718) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10723 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |