Vulnerabilities > CVE-2000-1134
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 6 | |
OS | 3 | |
OS | 1 | |
OS | 5 | |
OS | 5 | |
OS | 1 |
Exploit-Db
description UUCP Exploit - file creation/overwriting (symlinks). CVE-2000-1134. Local exploit for linux platform id EDB-ID:217 last seen 2016-01-31 modified 2000-12-04 published 2000-12-04 reporter t--zen source https://www.exploit-db.com/download/217/ title UUCP Exploit - file creation/overwriting symlinks description Mac OS X 10,HP-UX 9/10/11,Mandriva 6/7,RedHat 5/6,SCO 5,IRIX 6 Shell Redirection Race Condition. CVE-2000-1134. Local exploit for unix platform id EDB-ID:20436 last seen 2016-02-02 modified 2000-01-02 published 2000-01-02 reporter proton source https://www.exploit-db.com/download/20436/ title Mac OS X 10,HP-UX 9/10/11,Mandriva 6/7,RedHat 5/6,SCO 5,IRIX 6 Shell Redirection Race Condition
Nessus
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2000-075.NASL |
description | The bash1 shell program has the same << vulnerability that tcsh has and incorrectly creates temporary files without the O_EXCL flag. This vulnerability does not exist in bash2 which uses the O_EXCL flag when creating temporary files. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 61861 |
published | 2012-09-06 |
reporter | This script is Copyright (C) 2012-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/61861 |
title | Mandrake Linux Security Advisory : bash1 (MDKSA-2000:075) |
code |
|
Oval
accepted | 2006-09-27T12:29:23.796-04:00 | ||||||||||||
class | vulnerability | ||||||||||||
contributors |
| ||||||||||||
description | redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack. | ||||||||||||
family | unix | ||||||||||||
id | oval:org.mitre.oval:def:4047 | ||||||||||||
status | accepted | ||||||||||||
submitted | 2005-01-19T12:00:00.000-04:00 | ||||||||||||
title | Shell Redirect Symlink Attack Vulnerability | ||||||||||||
version | 36 |
Redhat
advisories |
|
References
- ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:76.tcsh-csh.asc
- ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0418.html
- http://archives.neohapsis.com/archives/tru64/2002-q1/0009.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000350
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000354
- http://marc.info/?l=bugtraq&m=97561816504170&w=2
- http://www.calderasystems.com/support/security/advisories/CSSA-2000-042.0.txt
- http://www.calderasystems.com/support/security/advisories/CSSA-2000-043.0.txt
- http://www.debian.org/security/2000/20001111a
- http://www.kb.cert.org/vuls/id/10277
- http://www.linux-mandrake.com/en/security/MDKSA-2000-069.php3
- http://www.linux-mandrake.com/en/security/MDKSA-2000-075.php3
- http://www.redhat.com/support/errata/RHSA-2000-117.html
- http://www.redhat.com/support/errata/RHSA-2000-121.html
- http://www.securityfocus.com/archive/1/146657
- http://www.securityfocus.com/bid/1926
- http://www.securityfocus.com/bid/2006
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4047