nano: multiple file editing insecurities
Published Apr 16, 2010
3.7
LOWCVSS 2.0
EPSS 0.28%
Description
Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, allows local user-assisted attackers to change the ownership of arbitrary files via vectors related to the creation of backup files.
Affected products
No data.
- ≤ 2.2.3
- 0.5.0
- 0.5.1
- 0.5.2
- 0.5.3
- 0.5.4
- 0.5.5
- 0.6.0
- 0.6.1
- 0.6.2
- 0.6.3
- 0.6.4
- 0.6.5
- 0.6.6
- 0.6.7
- 0.6.8
- 0.6.9
- 0.7.0
- 0.7.1
- 0.7.2
- 0.7.3
- 0.7.4
- 0.7.5
- 0.7.6
- 0.7.7
- 0.7.8
- 0.7.9
- 0.8.0
- 0.8.1
- 0.8.2
- 0.8.3
- 0.8.4
- 0.8.5
- 0.8.6
- 0.8.7
- 0.8.8
- 0.8.9
- 0.9.0
- 0.9.1
- 0.9.2
- 0.9.3
- 0.9.4
- 0.9.5
- 0.9.6
- 0.9.7
- 0.9.8
- 0.9.9
- 0.9.10
- 0.9.11
- 0.9.12
- 0.9.13
- 0.9.14
- 0.9.15
- 0.9.16
- 0.9.17
- 0.9.18
- 0.9.19
- 0.9.20
- 0.9.21
- 0.9.22
- 0.9.23
- 0.9.24
- 0.9.25
- 0.9.99pre1
- 0.9.99pre2
- 0.9.99pre3
- 1.0.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.0.9
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.1.7
- 1.1.8
- 1.1.9
- 1.1.10
- 1.1.11
- 1.1.12
- 1.1.99pre1
- 1.1.99pre2
- 1.1.99pre3
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.5
- 1.3.6
- 1.3.7
- 1.3.8
- 1.3.9
- 1.3.10
- 1.3.11
- 1.3.12
- 1.9.99pre1
- 1.9.99pre2
- 1.9.99pre3
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
- 2.1.0
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
- 2.1.5
- 2.1.6
- 2.1.7
- 2.1.8
- 2.1.9
- 2.1.10
- 2.1.11
- 2.1.99pre1
- 2.1.99pre2
- 2.2.0
- 2.2.1
- 2.2.2
No data.
Red Hat Enterprise Linux 4
nano
Will not fix
Red Hat Enterprise Linux 5
nano
Will not fix
Red Hat Enterprise Linux 6
nano
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | nano | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | nano | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | nano | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue was corrected in Red Hat Enterprise Linux 6 prior to its initial release. Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates for this or earlier releases. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (10)
- http://drosenbe.blogspot.com/2010/03/nano-as-root.html x_refsource_MISC
- http://lists.gnu.org/archive/html/nano-devel/2010-04/msg00000.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/39444 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://svn.savannah.gnu.org/viewvc/trunk/nano/ChangeLog?revision=4503&root=nano&view=markup x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2010/04/14/4 mailing-listx_refsource_MLIST
- http://www.securitytracker.com/id?1023891 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2010-1161 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=582434 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-1161
- https://www.cve.org/CVERecord?id=CVE-2010-1161
| Link | Providers | Tags |
|---|---|---|
| http://drosenbe.blogspot.com/2010/03/nano-as-root.html | x_refsource_MISC | |
| http://lists.gnu.org/archive/html/nano-devel/2010-04/msg00000.html | mailing-listx_refsource_MLIST | |
| http://secunia.com/advisories/39444 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://svn.savannah.gnu.org/viewvc/trunk/nano/ChangeLog?revision=4503&root=nano&view=markup | x_refsource_CONFIRM | |
| http://www.openwall.com/lists/oss-security/2010/04/14/4 | mailing-listx_refsource_MLIST | |
| http://www.securitytracker.com/id?1023891 | vdb-entryx_refsource_SECTRACK | |
| https://access.redhat.com/security/cve/CVE-2010-1161 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=582434 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-1161 | ||
| https://www.cve.org/CVERecord?id=CVE-2010-1161 |
Change history (0)
No recorded changes yet.