CVE-2001-0474: Low severity Brian Paul Mesa vulnerability
Published Jun 27, 2001
·Updated
Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.
Affected Software
2 affected components
Brian Paul Mesa<=3.3-14
Mandrakesoft Mandrake Linux=7.2
Remediation
Event History
Jun 27, 2001
CVE Published
04:00 AM
Sep 18, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0474?
CVE-2001-0474 is considered a local privilege escalation vulnerability.
2
How do I fix CVE-2001-0474?
To fix CVE-2001-0474, upgrade Mesa to version 3.3-15 or later.
3
What software is affected by CVE-2001-0474?
CVE-2001-0474 affects Mesa versions before 3.3-14 and Mandrake Linux 7.2.
4
What type of attack is described in CVE-2001-0474?
CVE-2001-0474 describes a symlink attack that allows local users to overwrite arbitrary files.
5
Is CVE-2001-0474 exploitable remotely?
No, CVE-2001-0474 is not remotely exploitable as it requires local access to the system.