// For flags

CVE-2001-1494

 

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2001-12-31 CVE Published
  • 2005-06-21 CVE Reserved
  • 2023-03-08 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Kernel
Search vendor "Kernel"
Util-linux
Search vendor "Kernel" for product "Util-linux"
< 2.11n
Search vendor "Kernel" for product "Util-linux" and version " < 2.11n"
-
Affected
Avaya
Search vendor "Avaya"
Cvlan
Search vendor "Avaya" for product "Cvlan"
*-
Affected
Avaya
Search vendor "Avaya"
Integrated Management Suit
Search vendor "Avaya" for product "Integrated Management Suit"
*-
Affected
Avaya
Search vendor "Avaya"
Interactive Response
Search vendor "Avaya" for product "Interactive Response"
*-
Affected
Avaya
Search vendor "Avaya"
Intuity Lx
Search vendor "Avaya" for product "Intuity Lx"
*-
Affected
Avaya
Search vendor "Avaya"
Message Networking
Search vendor "Avaya" for product "Message Networking"
*-
Affected
Avaya
Search vendor "Avaya"
Messaging Storage Server
Search vendor "Avaya" for product "Messaging Storage Server"
*-
Affected