Vulnerabilities > CVE-2001-0736
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
Application | 3 | |
OS | 4 | |
OS | 3 | |
OS | 1 |
Exploit-Db
description | University of Washington Pico 3.x/4.x File Overwrite Vulnerability. CVE-2001-0736. Local exploit for linux platform |
id | EDB-ID:20493 |
last seen | 2016-02-02 |
modified | 2000-12-11 |
published | 2000-12-11 |
reporter | mat |
source | https://www.exploit-db.com/download/20493/ |
title | University of Washington Pico 3.x/4.x File Overwrite Vulnerability |
Nessus
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2001-047.NASL |
description | Versions of the Pine email client prior to 4.33 have various temporary file creation problems, as does the pico editor. These issues allow any user with local system access to cause any files owned by any other user, including root, to potentially be overwritten if the conditions were right. Update : The packages for 7.1 and Corporate Server did not properly update the menu entries. These updated packages update the menu entries. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 13866 |
published | 2004-07-31 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/13866 |
title | Mandrake Linux Security Advisory : pine (MDKSA-2001:047-1) |
Redhat
advisories |
|
References
- http://marc.info/?l=bugtraq&m=98749102621604&w=2
- http://marc.info/?l=bugtraq&m=98749102621604&w=2
- http://marc.info/?l=bugtraq&m=99106787825229&w=2
- http://marc.info/?l=bugtraq&m=99106787825229&w=2
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-047.php3?dis=8.0
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-047.php3?dis=8.0
- http://www.redhat.com/support/errata/RHSA-2001-042.html
- http://www.redhat.com/support/errata/RHSA-2001-042.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6367
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6367