CVE-2010-1160

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
16/04/2010
Last modified:
11/04/2025

Description

GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:nano:*:*:*:*:*:*:*:* 2.2.3 (including)
cpe:2.3:a:gnu:nano:0.5.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.5.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.5.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.5.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.5.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.5.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.6.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.6.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.6.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.6.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.6.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:nano:0.6.7:*:*:*:*:*:*:*