Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2000-1134

29
FAUCET Score

CVE-2000-1134 describes a local file overwrite vulnerability affecting multiple Unix shell programs, including tcsh, csh, sh, and bash, across various distributions like Red Hat, SuSE, and Mandrakesoft. The flaw allows local users to overwrite arbitrary files of other users by exploiting how these shells follow symlinks during "here-document" processing. Rated with a CVSS score of 7.2 (High), this vulnerability has a high impact on confidentiality, integrity, and availability, requiring local access but no authentication. While not listed on CISA's KEV catalog, exploit code for similar symlink race conditions exists on ExploitDB, though there is no evidence of active exploitation or significant community discussion for this specific CVE.

Impacted Technologies

VendorProductVersion(s)CPE
6.2CPE matchmatch criteria
cpe:2.3:a:immunix:immunix:6.2:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:conectiva:linux:4.0:*:*:*:*:*:*:*
4.0esCPE matchmatch criteria
cpe:2.3:o:conectiva:linux:4.0es:*:*:*:*:*:*:*
4.1CPE matchmatch criteria
cpe:2.3:o:conectiva:linux:4.1:*:*:*:*:*:*:*
4.2CPE matchmatch criteria
cpe:2.3:o:conectiva:linux:4.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.42%
Probability of exploitation in next 30 days
EPSS Percentile
69.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-217 · Dec 4, 2000
This CVE's current EPSS score of 0.0141 is in the 86th percentile among its peer group of 3,237 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Linux 5.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 6.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 7.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 7.0j
View patch

Vendor Advisories (1)

redhatCVE-2000-1134

security flaw

Oct 28, 2000

References

ftp.freebsd.org / pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:76.tcsh-csh.asc
PatchVendor Advisory
patches.sgi.com / support/free/security/advisories/20011103-02-P
archives.neohapsis.com / archives/bugtraq/2000-10/0418.html
archives.neohapsis.com / archives/tru64/2002-q1/0009.html
distro.conectiva.com.br / atualizacoes
distro.conectiva.com.br / atualizacoes
marc.info
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4047
calderasystems.com / support/security/advisories/CSSA-2000-042.0.txt
calderasystems.com / support/security/advisories/CSSA-2000-043.0.txt
debian.org / security/2000/20001111a
kb.cert.org / vuls/id/10277
US Government Resource
linux-mandrake.com / en/security/MDKSA-2000-069.php3
linux-mandrake.com / en/security/MDKSA-2000-075.php3
redhat.com / support/errata/RHSA-2000-117.html
redhat.com / support/errata/RHSA-2000-121.html
securityfocus.com / archive/1/146657
securityfocus.com / bid/1926
securityfocus.com / bid/2006
ExploitPatchVendor Advisory