CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2701 | CVE-2000-1134 | Candidate | Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack. | Modified (20061101) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> XF:linux-bash-tmp-symlink(5593) | Christey> Don"t all these shell programs originate from the same | codebase, including ksh? If so, we should have a single CAN | for all of these, and add: | XF:ksh-redirection-symlink | URL:http://xforce.iss.net/static/5811.php | CONECTIVA:CLA-2000:354 | BUGTRAQ:20001208 Immunix OS Security update for tcsh | http://archives.neohapsis.com/archives/linux/immunix/2000-q4/0041.html | BUGTRAQ:20001220 /bin/ksh creates insecure tmp files | http://archives.neohapsis.com/archives/bugtraq/2000-12/0368.html | BUGTRAQ:20001227 IBM Findings: Korn Shell Redirection Race Condition Vulnerability | http://archives.neohapsis.com/archives/bugtraq/2000-12/0473.html | | Also see: http://archives.neohapsis.com/archives/bugtraq/2000-12/0420.html | which gives some shell history which may be of use. | Christey> ADDREF FREEBSD:FreeBSD-SA-01:03 for the bash problem. | Christey> Consider adding BID:2148 if this CAN should include ksh | Christey> SGI:20011103-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20011103-01-I | Also, DELREF BID:2148 and BID:1926. Keep BID:2006 | Christey> COMPAQ:SSRT1-41U | URL:http://ftp.support.compaq.com/patches/.new/html/SSRT0742U-59U.shtml | CERT-VN:VU#10277 | URL:http://www.kb.cert.org/vuls/id/10277 | Christey> SGI:20011103-02-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P | Note that this is an update of the other SGI reference. | Christey> CALDERA:CSSA-2001-SCO.24 | URL:ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.24.1/CSSA-2001-SCO.24.1.txt | CERT-VN:VU#10277 | URL:http://www.kb.cert.org/vuls/id/10277 | Christey> Missing BID - BID:1926 | Christey> HP:SSRT3618 | URL:http://archives.neohapsis.com/archives/hp/2003-q3/0042.html | View |
2702 | CVE-2000-1135 | Entry | fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack. | View | |||
2703 | CVE-2000-1136 | Entry | elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack. | View | |||
2704 | CVE-2000-1137 | Entry | GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack. | View | |||
2705 | CVE-2000-1138 | Candidate | Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected. | Proposed (20001219) | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:lotus-notes-r5-mime(5492) | View |
Page 541 of 20943, showing 5 records out of 104715 total, starting on record 2701, ending on 2705