CVE-2001-1494

CWE-597 documents7 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 76.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 30

Description

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDkernel/util-linux< 2.11n
Debianutil-linux< 2.11n-1+3

🔴Vulnerability Details

3
GHSA
GHSA-8gpj-8888-5722: script command in the util-linux package before 22022-04-30
CVEList
CVE-2001-1494: script command in the util-linux package before 22005-06-21
OSV
CVE-2001-1494: script command in the util-linux package before 22001-12-31

📋Vendor Advisories

2
Red Hat
security flaw2001-12-12
Debian
CVE-2001-1494: util-linux - script command in the util-linux package before 2.11n allows local users to over...2001

💬Community

1
Bugzilla
CVE-2001-1494 security flaw2018-08-16