CVE-2000-1137: Medium severity GNU ed vulnerability
Published Jan 9, 2001
·Updated
GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.
Affected Software
4 affected components
GNU ed=2.15
GNU ed=2.16tr
GNU ed=2.18
GNU ed=2.18.0
Remediation
Patch Available
Event History
Jan 9, 2001
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1137?
CVE-2000-1137 is considered a moderate severity vulnerability due to its potential for local file manipulation.
2
How do I fix CVE-2000-1137?
To fix CVE-2000-1137, upgrade GNU ed to version 2.18 or later.
3
Who is affected by CVE-2000-1137?
Local users on systems running affected versions of GNU ed, specifically versions before 0.2-18.1, are at risk from CVE-2000-1137.
4
What types of attacks does CVE-2000-1137 enable?
CVE-2000-1137 enables local users to conduct symlink attacks to overwrite files of other users.
5
Which versions of GNU ed are vulnerable to CVE-2000-1137?
GNU ed versions 2.15, 2.16tr, and 2.18 (up to but not including 2.18.1) are vulnerable to CVE-2000-1137.