First published: Mon Sep 10 2001(Updated: )
msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Tru64 UNIX | =4.0d | |
HP Tru64 UNIX | =4.0e | |
HP Tru64 UNIX | =4.0f | |
HP Tru64 UNIX | =4.0g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1092 is considered a low-risk vulnerability as it only affects local users.
To fix CVE-2001-1092, ensure that the .mh_profile file is not writable or modify permissions to prevent symlink attacks.
CVE-2001-1092 affects local users on Digital UNIX versions 4.0G and earlier.
CVE-2001-1092 is associated with a symlink attack that allows unauthorized access to the first line of arbitrary files.
The implications of CVE-2001-1092 include potential data exposure for sensitive information stored in files accessible by local users.