CVE-2001-0138: Low severity Immunix Immunix vulnerability
Published Mar 12, 2001
·Updated
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
Affected Software
14 affected components
Immunix Immunix=7.0_beta
Mandrakesoft Mandrake Linux=7.2
Debian Debian Linux=2.2
Debian Debian Linux=2.2
redhat Linux=7.0
Mandrakesoft Mandrake Linux=7.0
Debian Debian Linux=2.2
Mandrakesoft Mandrake Linux Corporate Server=1.0.1
Mandrakesoft Mandrake Linux=7.1
Mandrakesoft Mandrake Linux=6.0
Debian Debian Linux=2.2
Debian Debian Linux=2.2
Mandrakesoft Mandrake Linux=6.1
Debian Debian Linux=2.2
Remediation
Patch Available
Event History
Mar 12, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0138?
CVE-2001-0138 is considered to have a high severity due to its potential for local users to exploit symlink attacks.
2
How do I fix CVE-2001-0138?
To fix CVE-2001-0138, update the wu-ftpd program to version 2.6.1-6 or later.
3
Which software is affected by CVE-2001-0138?
CVE-2001-0138 affects wu-ftpd before version 2.6.1-6 on various Linux distributions including Immunix, Mandrake, and Debian.
4
What type of attack is associated with CVE-2001-0138?
CVE-2001-0138 is associated with a symlink attack that allows local users to overwrite arbitrary files.
5
Who is at risk from CVE-2001-0138?
Local users with access to the affected systems are at risk from CVE-2001-0138.