First published: Tue Dec 11 2001(Updated: )
Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SANE Project SANE Backends | =1.0.0 | |
SANE Project SANE Backends | =1.0.1 | |
SANE Project SANE Backends | =1.0.2 | |
SANE Project SANE Backends | =1.0.3 | |
SANE Project SANE Backends | =1.0.4 | |
SANE Project SANE Backends | =1.0.5 | |
SANE Project SANE Backends | =1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0890 has been classified as a medium-severity vulnerability due to its potential for local file modification.
CVE-2001-0890 allows local users to exploit symlink attacks on temporary files, leading to unauthorized file modifications.
CVE-2001-0890 affects SANE library versions 1.0.0 through 1.0.3.
To fix CVE-2001-0890, upgrade to SANE library version 1.0.4 or later.
No, CVE-2001-0890 is not a remote exploit; it requires local user access to the system.