PT-2010-2875 · Gnu+1 · Gnu Nano+1
Dan Rosenberg
·
Publicado
2010-04-16
·
Atualizado
2024-06-15
·
CVE-2010-1161
CVSS v2.0
3.7
Baixa
| Vetor | AV:L/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GNU nano versions prior to 2.2.4
Description
A race condition exists when GNU nano is run by root to edit a file not owned by root, allowing local user-assisted attackers to change the ownership of arbitrary files through vectors related to the creation of backup files.
Recommendations
For versions prior to 2.2.4, update to version 2.2.4 or later to resolve the issue.
Correção
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gnu Nano
Nano