PT-2001-1026 · Gnu · Diffutils
Published
2001-03-12
·
Updated
2017-10-10
·
CVE-2001-0117
CVSS v2.0
1.2
Low
| Vector | AV:L/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
diffutils version 2.7
Description
The issue allows local users to overwrite files via a symlink attack, potentially leading to integrity violations of protected information. This can be exploited locally.
Recommendations
For version 2.7, consider restricting access to sensitive files and directories to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the
sdiff command in scenarios where file overwriting could have significant consequences.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Diffutils