First published: Mon Mar 12 2001(Updated: )
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | =7.0_beta | |
Debian | =2.2 | |
Debian | =2.2 | |
Debian | =2.2 | |
Debian | =2.2 | |
Debian | =2.2 | |
Debian | =2.2 | |
Mandrake Linux | =6.0 | |
Mandrake Linux | =6.1 | |
Mandrake Linux | =7.0 | |
Mandrake Linux | =7.1 | |
Mandrake Linux | =7.2 | |
Mandriva Linux Corporate Server | =1.0.1 | |
Red Hat Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0138 is considered to have a high severity due to its potential for local users to exploit symlink attacks.
To fix CVE-2001-0138, update the wu-ftpd program to version 2.6.1-6 or later.
CVE-2001-0138 affects wu-ftpd before version 2.6.1-6 on various Linux distributions including Immunix, Mandrake, and Debian.
CVE-2001-0138 is associated with a symlink attack that allows local users to overwrite arbitrary files.
Local users with access to the affected systems are at risk from CVE-2001-0138.