CVE-2001-0140: Low severity Immunix Immunix vulnerability
Published Mar 12, 2001
·Updated
arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
Affected Software
7 affected components
Immunix Immunix=7.0_beta
Mandrakesoft Mandrake Linux=6.0
Mandrakesoft Mandrake Linux=6.1
Mandrakesoft Mandrake Linux=7.0
Mandrakesoft Mandrake Linux=7.1
Mandrakesoft Mandrake Linux=7.2
redhat Linux=7.0
Remediation
Patch Available
Event History
Mar 12, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0140?
CVE-2001-0140 is considered to have a moderate severity rating due to its potential to allow local users to overwrite arbitrary files.
2
How do I fix CVE-2001-0140?
To mitigate CVE-2001-0140, users should avoid using symlinked files in configurations related to arpwatch.
3
Which systems are affected by CVE-2001-0140?
CVE-2001-0140 affects various versions of Immunix, Mandrake Linux, and Red Hat Linux.
4
Can remote users exploit CVE-2001-0140?
CVE-2001-0140 is specifically a local vulnerability, meaning it cannot be exploited by remote users.
5
Is there a patch available for CVE-2001-0140?
There is no specific patch for CVE-2001-0140; the recommended action is to review and change configuration settings to eliminate symlink vulnerabilities.