← Back

CVE-2000-1134

nvd nist
Published: Jan 9, 2001Modified: Apr 16, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

Affected (22)

Show all products
1 product
Linux
1 product
Immunix
3 products
Openlinux
Openlinux Edesktop
Openlinux Eserver
1 product
Hp Ux
1 product
Mandrake Linux
1 product
Linux
1 product
Suse Linux
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Conectiva
Version 4.0
Version 4.0es
Version 4.1
Version 4.2
Version 5.0
Version 5.1
Version 6.2
Configuration B
15 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Version 2.4
Version 2.3
Version 11.11
Mandrakesoft
Version 6.0
Version 6.1
Version 7.0
Version 7.1
Version 7.2
Redhat
Version 5.2
Version 6.0
Version 6.1
Version 6.2
Version 6.2e
Version 7.0

References (38)

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:76.tcsh-csh.asc (unsafe URL)
Source: cve@mitre.org
PatchVendor Advisory
ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
ExploitPatchVendor Advisory
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:76.tcsh-csh.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory

Timeline

No history available yet.