CVE-2001-1092 describes a local information disclosure vulnerability in the msgchk utility within Digital UNIX 4.0G and earlier, specifically affecting Compaq Tru64. A local attacker can exploit this by creating a symbolic link to an arbitrary file, masquerading it as the .mh_profile file, allowing them to read the first line of that file. With a CVSS score of 2.1 (LOW), this vulnerability has a low attack complexity and only impacts confidentiality, as it allows for partial information disclosure. While not listed on CISA's KEV or Hot List, an ExploitDB entry (EDB-21107) exists, indicating public exploit code availability, and it has garnered a notable amount of community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0dCPE matchmatch criteria | cpe:2.3:o:compaq:tru64:4.0d:*:*:*:*:*:*:* | ||
4.0eCPE matchmatch criteria | cpe:2.3:o:compaq:tru64:4.0e:*:*:*:*:*:*:* | ||
4.0fCPE matchmatch criteria | cpe:2.3:o:compaq:tru64:4.0f:*:*:*:*:*:*:* | ||
4.0gCPE matchmatch criteria | cpe:2.3:o:compaq:tru64:4.0g:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.