PT-2001-1518 · Joe · Joe

Published

2001-05-03

·

Updated

2008-09-05

·

CVE-2001-0289

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Joe text editor version 2.8
Description The issue allows local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory. This occurs because Joe text editor searches the current working directory for the .joerc configuration file.
Recommendations For Joe text editor version 2.8, consider restricting access to the .joerc configuration file to prevent unauthorized modifications, and avoid executing joe from untrusted directories until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0289

Affected Products

Joe