CVE
- Id
- 3369
- CVE No.
- CVE-2001-0556
- Status
- Candidate
- Description
- The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users" files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.
- Phase
- Proposed (20010727)
- Votes
- ACCEPT(6) Baker, Bishop, Cole, Foat, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall
- Comments
- Frech> nedit-print-symlink(6424) | Christey> SGI:20011105-01-P | ftp://patches.sgi.com/support/free/security/advisories/20011105-01-P | ADDREF BID:2627 | URL:http://www.securityfocus.com/bid/2627 | (there are different BID"s for the different symlink issues)