CVE-2001-1494 describes a local privilege escalation vulnerability in the 'script' command of the util-linux package (versions prior to 2.11n), also affecting Avaya and Linux kernel products. An authenticated local attacker can overwrite arbitrary files by creating a hardlink from the 'typescript' log file to any system file, then tricking root into executing the 'script' command. This medium-severity vulnerability (CVSS 5.5) has low attack complexity and requires local access, but can lead to high integrity impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11nCPE matchmatch criteria | cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:avaya:cvlan:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:avaya:integrated_management_suit:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:avaya:interactive_response:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:avaya:intuity_lx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.