VU#440539Third-party advisory
http://www.kb.cert.org/vuls/id/440539 CVE-2001-1092
Digital Unix 4.0 - MSGCHK MH_PROFILE Symbolic Link
Record summary
CVE-2001-1092 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDigital Unix 4.0 - MSGCHK MH_PROFILE Symbolic LinkExploitDB exploitby seoNot analyzed1 file
References
520010910 Digital Unix 4.0x msgchk multiple vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/213238 3320vdb entry
http://www.securityfocus.com/bid/3320 du-msgchk-symlink(7102)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/7102 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1092