~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
Candidate: CVE-2010-1160
PublicDate: 2010-04-16
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1160
 http://svn.savannah.gnu.org/viewvc/trunk/nano/ChangeLog?revision=4503&root=nano&view=markup
 http://drosenbe.blogspot.com/2010/03/nano-as-root.html
Description:
 GNU nano before 2.2.4 does not verify whether a file has been changed
 before it is overwritten in a file-save operation, which allows local
 user-assisted attackers to overwrite arbitrary files via a symlink attack
 on an attacker-owned file that is being edited by the victim.
Ubuntu-Description:
Notes:
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577817
 https://bugs.launchpad.net/ubuntu/+source/nano/+bug/535400
 https://bugs.launchpad.net/ubuntu/+source/nano/+bug/564734
Priority: low
Discovered-by:
Assigned-to:

Patches_nano:
upstream_nano: released (2.2.4)
dapper_nano: ignored (reached end-of-life)
hardy_nano: ignored (reached end-of-life)
intrepid_nano: needed (reached end-of-life)
jaunty_nano: ignored (reached end-of-life)
karmic_nano: ignored (reached end-of-life)
lucid_nano: ignored (reached end-of-life)
maverick_nano: not-affected (2.2.4-1)
natty_nano: not-affected (2.2.4-1)
oneiric_nano: not-affected (2.2.4-1)
precise_nano: not-affected (2.2.4-1)
quantal_nano: not-affected (2.2.4-1)
raring_nano: not-affected (2.2.4-1)
saucy_nano: not-affected (2.2.4-1)
trusty_nano: not-affected (2.2.4-1)
utopic_nano: not-affected (2.2.4-1)
vivid_nano: not-affected (2.2.4-1)
devel_nano: not-affected (2.2.4-1)