First published: Tue Aug 14 2001(Updated: )
OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSH | <=2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0529 is considered a medium severity vulnerability due to its potential impact on file integrity through local symlink attacks.
To fix CVE-2001-0529, upgrade OpenSSH to version 2.9 or later with X forwarding disabled if upgrade is not possible.
CVE-2001-0529 affects users running OpenSSH version 2.9 and earlier with X forwarding enabled on their systems.
CVE-2001-0529 can be exploited by local attackers using symlink attacks to delete files named 'cookies'.
A possible workaround for CVE-2001-0529 is to disable X forwarding in your OpenSSH configuration to mitigate the risk.