OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.
Link | Tags |
---|---|
http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-034-01 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6676 | vdb entry |
http://www.openbsd.org/errata29.html | vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2001-05/0322.html | vendor advisory mailing list exploit |
http://archives.neohapsis.com/archives/bugtraq/2001-06/0007.html | vendor advisory mailing list |
http://online.securityfocus.com/archive/1/188737 | mailing list |
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-010.txt.asc | patch vendor advisory |
http://www.calderasystems.com/support/security/advisories/CSSA-2001-023.0.txt | vendor advisory |
http://www.kb.cert.org/vuls/id/655259 | third party advisory us government resource |
http://www.securityfocus.com/bid/2825 | patch vendor advisory vdb entry exploit |
http://www.osvdb.org/1853 | vdb entry |
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000431 | vendor advisory |