2.1
CVSSv2

CVE-2001-1092

Published: 10/09/2001 Updated: 19/12/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

msgchk in Digital UNIX 4.0G and previous versions allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file.

Vulnerable Product Search on Vulmon Subscribe to Product

compaq tru64 4.0f

compaq tru64 4.0g

compaq tru64 4.0d

compaq tru64 4.0e

Exploits

source: wwwsecurityfocuscom/bid/3320/info The msgchk utility under certain versions of Digital Unix contains an information disclosure vulnerability which could yield root privilege Because msgchk fails to check file permissions before opening user configuration files in the user's home directory, a symbolic link to a target file can pe ...

Github Repositories

Hi there πŸ‘‹ Trails Senior Security Engineer, GREE πŸ‡―πŸ‡΅ 2012, Now ~ Security Manager, LINE πŸ‡―πŸ‡΅ 2008, 4 and half years Co-founder, PanicSecurity πŸ‡°πŸ‡· (PS ScanW3B) 2004 Security Engineer, Webzen πŸ‡°πŸ‡· 2003, 2years Security Consultant, HackersLab πŸ‡°πŸ‡· (The first security consulting firm in Korea) 2001, 2years Founder, IGRUS, Inha Group of Research for UNIX