Symlink attack in Linux kernel - CVE-2000-1134
Published: January 9, 2001 / Updated: July 14, 2020
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.