First published: Mon Mar 12 2001(Updated: )
arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Immunix | =7.0_beta | |
Mandrake Linux | =7.2 | |
Red Hat Linux | =7.0 | |
Mandrake Linux | =7.0 | |
Mandrake Linux | =7.1 | |
Mandrake Linux | =6.0 | |
Mandrake Linux | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0140 is considered to have a moderate severity rating due to its potential to allow local users to overwrite arbitrary files.
To mitigate CVE-2001-0140, users should avoid using symlinked files in configurations related to arpwatch.
CVE-2001-0140 affects various versions of Immunix, Mandrake Linux, and Red Hat Linux.
CVE-2001-0140 is specifically a local vulnerability, meaning it cannot be exploited by remote users.
There is no specific patch for CVE-2001-0140; the recommended action is to review and change configuration settings to eliminate symlink vulnerabilities.