CVE-2000-1134

Description

Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.177

Associated Vulnerability

VulnerabilityOS Platform
Kernel-uek update (ELSA-2020-5913) kernel-uek-4.14.35-2025.402.2.1.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2020-5913) kernel-uek-debug-4.14.35-2025.402.2.1.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2020-5913) kernel-uek-debug-devel-4.14.35-2025.402.2.1.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2020-5913) kernel-uek-devel-4.14.35-2025.402.2.1.el7uek.x86_64.rpmLinux
Kernel-uek-tools update (ELSA-2020-5913) kernel-uek-tools-4.14.35-2025.402.2.1.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2020-5913) kernel-uek-doc-4.14.35-2025.402.2.1.el7uek.noarch.rpmLinux
Multiple Vulnerabilities affected in hp-ux 11.11NCM
CVE-2000-1134NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234