CVE-2001-0142: Low severity Immunix Immunix vulnerability
Published Mar 12, 2001
·Updated
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
Affected Software
10 affected components
Immunix Immunix=7.0_beta
National Science Foundation Squid Web Proxy=2.3_stable4
Mandrakesoft Mandrake Linux=6.0
Mandrakesoft Mandrake Linux=6.1
Mandrakesoft Mandrake Linux=7.0
Mandrakesoft Mandrake Linux=7.1
Mandrakesoft Mandrake Linux=7.2
redhat Linux=7.0
Trustix Secure Linux=1.1
Trustix Secure Linux=1.2
Remediation
Patch Available
Event History
Mar 12, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0142?
CVE-2001-0142 is classified as a medium severity vulnerability.
2
How do I fix CVE-2001-0142?
To fix CVE-2001-0142, upgrade to a version of Squid that is later than 2.3 or apply appropriate security patches provided by your Linux distribution.
3
Who is affected by CVE-2001-0142?
CVE-2001-0142 affects users of Squid versions 2.3 and earlier on various Linux distributions such as Red Hat, Mandrake, and Trustix.
4
What is the nature of CVE-2001-0142?
CVE-2001-0142 is a symlink attack vulnerability that allows local users to overwrite arbitrary files in certain configurations.
5
Can CVE-2001-0142 be mitigated without an upgrade?
Mitigation of CVE-2001-0142 without an upgrade can be challenging, but restricting user permissions on affected directories may help.