PT-2000-1928 · Gnu · Shred
Published
2000-12-11
·
Updated
2017-10-10
·
CVE-2000-1018
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
shred version 1.0
Description
The issue is related to the shred file wiping utility, which fails to properly open a file for overwriting or flush its buffers. This prevents shred from correctly replacing the file's data, allowing local users to recover the file.
Recommendations
For version 1.0, consider using an alternative file wiping method until a patch is available. As a temporary workaround, manually verify that files are properly overwritten after using shred to minimize the risk of data recovery.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Shred