4.6

CVE-2001-0289

Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Joseph AllenJoe Version2.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.74% 0.498
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2001-02/0490.html
Patch
Vendor Advisory
http://www.debian.org/security/2001/dsa-041
Patch
Vendor Advisory
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-026.php3
Patch
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2001-024.html