CVE-2001-0529: High severity OpenBSD OpenSSH vulnerability
Published Aug 14, 2001
·Updated
OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.
Affected Software
1 affected component
OpenBSD OpenSSH<=2.9
Remediation
Patch Available
Event History
Aug 14, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0529?
CVE-2001-0529 is considered a medium severity vulnerability due to its potential impact on file integrity through local symlink attacks.
2
How do I fix CVE-2001-0529?
To fix CVE-2001-0529, upgrade OpenSSH to version 2.9 or later with X forwarding disabled if upgrade is not possible.
3
Who is affected by CVE-2001-0529?
CVE-2001-0529 affects users running OpenSSH version 2.9 and earlier with X forwarding enabled on their systems.
4
What types of attacks can exploit CVE-2001-0529?
CVE-2001-0529 can be exploited by local attackers using symlink attacks to delete files named 'cookies'.
5
Is there any workaround for CVE-2001-0529?
A possible workaround for CVE-2001-0529 is to disable X forwarding in your OpenSSH configuration to mitigate the risk.