CVE-2001-0109: Low severity SUSE SuSE Linux vulnerability
Published Mar 12, 2001
·Updated
rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.
Affected Software
5 affected components
SUSE SuSE Linux=6.2
SUSE SuSE Linux=6.1
SUSE SuSE Linux=7.0
SUSE SuSE Linux=6.3
SUSE SuSE Linux=6.4
Remediation
Patch Available
Event History
Mar 12, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0109?
CVE-2001-0109 is considered a high severity vulnerability due to its potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2001-0109?
To fix CVE-2001-0109, ensure that the rctab application does not use predictable temporary filenames or implement proper symlink validation.
3
Which versions of SUSE Linux are affected by CVE-2001-0109?
CVE-2001-0109 affects SUSE Linux versions 6.1, 6.2, 6.3, 6.4, and 7.0.
4
What is a symlink attack in the context of CVE-2001-0109?
In the context of CVE-2001-0109, a symlink attack allows local users to exploit temporary files to overwrite sensitive files by manipulating symbolic links.
5
Can CVE-2001-0109 be exploited remotely?
No, CVE-2001-0109 can only be exploited locally by authenticated users.