CVE-2001-1494

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.

Open
LOW (3.4)
  • T

    Tim Bastin detected CVE-2001-1494 with a risk of 3.35

  • logo

    System updated the risk assessment to 1.67

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment to 3.35

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment to 1.67

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 1.67 to 3.35

    System recalculated raw risk assessment

  • logo

    System fixed CVE-2001-1494

  • logo

    System detected CVE-2001-1494 with a risk of 3.35

Add a comment

Mark as False Positive
Last calculated at:

Affected component

Logo von deb debian/util-linux

Installed version:
2.38.1-5
Fixed in:
2.11n-1

Quick Fix

Update all Dependencies
Update only debian/util-linux
Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 667098114b5ef45c7830e7aa599604fa65eb818f