CVE-2000-1134 describes a local file overwrite vulnerability affecting multiple Unix shell programs, including tcsh, csh, sh, and bash, across various distributions like Red Hat, SuSE, and Mandrakesoft. The flaw allows local users to overwrite arbitrary files of other users by exploiting how these shells follow symlinks during "here-document" processing. Rated with a CVSS score of 7.2 (High), this vulnerability has a high impact on confidentiality, integrity, and availability, requiring local access but no authentication. While not listed on CISA's KEV catalog, exploit code for similar symlink race conditions exists on ExploitDB, though there is no evidence of active exploitation or significant community discussion for this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.2CPE matchmatch criteria | cpe:2.3:a:immunix:immunix:6.2:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:conectiva:linux:4.0:*:*:*:*:*:*:* | ||
4.0esCPE matchmatch criteria | cpe:2.3:o:conectiva:linux:4.0es:*:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:o:conectiva:linux:4.1:*:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:o:conectiva:linux:4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.