Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9v2x-x2qc-4cfg

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.

GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.

EPSS

Процентиль: 18%
0.00058
Низкий

Дефекты

CWE-59

Связанные уязвимости

ubuntu
больше 15 лет назад

GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.

redhat
больше 15 лет назад

GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.

nvd
больше 15 лет назад

GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.

debian
больше 15 лет назад

GNU nano before 2.2.4 does not verify whether a file has been changed ...

EPSS

Процентиль: 18%
0.00058
Низкий

Дефекты

CWE-59