First published: Mon Mar 12 2001(Updated: )
rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =6.1 | |
SUSE Linux | =6.2 | |
SUSE Linux | =6.3 | |
SUSE Linux | =6.4 | |
SUSE Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0109 is considered a high severity vulnerability due to its potential for local users to overwrite arbitrary files.
To fix CVE-2001-0109, ensure that the rctab application does not use predictable temporary filenames or implement proper symlink validation.
CVE-2001-0109 affects SUSE Linux versions 6.1, 6.2, 6.3, 6.4, and 7.0.
In the context of CVE-2001-0109, a symlink attack allows local users to exploit temporary files to overwrite sensitive files by manipulating symbolic links.
No, CVE-2001-0109 can only be exploited locally by authenticated users.