Record summary

CVE-2000-1134 has a selected CVSS score of 7.2; EIP currently links 2 catalogued exploits.

Description

Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBApple Mac OSX 10 / HP-UX 9/10/11 / Mandriva 6/7 / RedHat 5/6 / SCO 5 / IRIX 6 - Shell Redirection Race ConditionExploitDB exploitby protonNot analyzed1 file
ExploitDB

PoC details
ExploitDBUUCP - File Creation/Overwriting SymlinksExploitDB exploitby t--zenNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 18