Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2001-0736

6 documents6 sources
Severity
2.1LOW
EPSS
0.2%
top 61.16%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 18
Latest updateApr 30

Description

Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages6 packages

NVDredhat/linux5.2, 6.2, 7.0+2
NVDimmunix/immunix6.2, 7.0, 7.0_beta+2
NVDmandrakesoft/mandrake_linux7.1, 7.2, 8.0+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xqxf-jjq4-grw6: Vulnerability in (1) pine before 42022-04-30
CVEList
CVE-2001-0736: Vulnerability in (1) pine before 42001-10-12

💥Exploits & PoCs

1
Exploit-DB
University of Washington Pico 3.x/4.x - File Overwrite2000-12-11

📋Vendor Advisories

1
Red Hat
security flaw2001-03-31

💬Community

1
Bugzilla
CVE-2001-0736 security flaw2018-08-16
CVE-2001-0736 (LOW CVSS 2.1) | Vulnerability in (1) pine before 4. | cvebase.io