CVE-2001-0890: Low severity SANE SANE vulnerability
Published Dec 11, 2001
·Updated
Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.
Affected Software
7 affected components
SANE SANE=1.0.0
SANE SANE=1.0.1
SANE SANE=1.0.2
SANE SANE=1.0.3
SANE SANE=1.0.4
SANE SANE=1.0.5
SANE SANE=1.0.6
Remediation
Patch Available
Patch Available
Event History
Dec 11, 2001
CVE Published
05:00 AM
Jul 23, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0890?
CVE-2001-0890 has been classified as a medium-severity vulnerability due to its potential for local file modification.
2
How does CVE-2001-0890 affect users?
CVE-2001-0890 allows local users to exploit symlink attacks on temporary files, leading to unauthorized file modifications.
3
Which versions of SANE are impacted by CVE-2001-0890?
CVE-2001-0890 affects SANE library versions 1.0.0 through 1.0.3.
4
How can I remediate CVE-2001-0890?
To fix CVE-2001-0890, upgrade to SANE library version 1.0.4 or later.
5
Is CVE-2001-0890 a remote exploit?
No, CVE-2001-0890 is not a remote exploit; it requires local user access to the system.