CVE-2010-1160: Low severity GNU Nano vulnerability
GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1160?
The severity of CVE-2010-1160 is classified as medium, due to its potential for local user-assisted exploitation.
How do I fix CVE-2010-1160?
To fix CVE-2010-1160, update to GNU nano version 2.2.4 or later, where the vulnerability has been addressed.
What systems are affected by CVE-2010-1160?
CVE-2010-1160 affects multiple versions of GNU nano including versions from 0.5.0 up to 2.2.3.
What type of attack is associated with CVE-2010-1160?
CVE-2010-1160 is associated with a symlink attack that allows local user-assisted attackers to overwrite arbitrary files.
Is CVE-2010-1160 a remote or local vulnerability?
CVE-2010-1160 is a local vulnerability that requires user interaction for exploitation.