CVE-2001-1092: Low severity compaq tru64 vulnerability
Published Sep 10, 2001
·Updated
msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mhprofile file.
Affected Software
4 affected components
Compaq Tru64=4.0d
Compaq Tru64=4.0g
Compaq Tru64=4.0f
Compaq Tru64=4.0e
Event History
Sep 10, 2001
CVE Published
04:00 AM
Mar 15, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1092?
CVE-2001-1092 is considered a low-risk vulnerability as it only affects local users.
2
How do I fix CVE-2001-1092?
To fix CVE-2001-1092, ensure that the .mh_profile file is not writable or modify permissions to prevent symlink attacks.
3
Who is affected by CVE-2001-1092?
CVE-2001-1092 affects local users on Digital UNIX versions 4.0G and earlier.
4
What type of attack is associated with CVE-2001-1092?
CVE-2001-1092 is associated with a symlink attack that allows unauthorized access to the first line of arbitrary files.
5
What are the implications of CVE-2001-1092?
The implications of CVE-2001-1092 include potential data exposure for sensitive information stored in files accessible by local users.