script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2001-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2001-1494
Mitre link : CVE-2001-1494
CVE.ORG link : CVE-2001-1494
JSON object : View
Products Affected
avaya
- intuity_lx
- messaging_storage_server
- message_networking
- integrated_management_suit
- interactive_response
- cvlan
kernel
- util-linux
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')