Description
Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, allows local user-assisted attackers to change the ownership of arbitrary files via vectors related to the creation of backup files.
CVSS vector
AV:L/AC:H/C:P/I:P/A:PExploitability: 1.9 | Impact: 6.4 Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-q9pv-rh5p-8836: Race condition in GNU nano before 2↗2022-05-02 ▶ OSVCVE-2010-1161: Race condition in GNU nano before 2↗2010-04-16 ▶ CVEListCVE-2010-1161: Race condition in GNU nano before 2↗2010-04-16 ▶ 📋Vendor Advisories
2Red Hatnano: multiple file editing insecurities↗2010-04-02 ▶ DebianCVE-2010-1161: nano - Race condition in GNU nano before 2.2.4, when run by root to edit a file that is...↗2010 ▶ 💬Community
3BugzillaCVE-2010-1160, CVE-2010-1161 nano: multiple file editing insecurities [fedora-all]↗2010-04-15 ▶ BugzillaCVE-2010-1160 CVE-2010-1161 nano: multiple file editing insecurities↗2010-04-14 ▶ BugzillaCVE-2010-1028 firefox: unspecified code execution vulnerability (VulnDisco 9.0)↗2010-02-18 ▶