GNU nano before 2.2.4 does not verify whether a file has...
Low severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Apr 16, 2010
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Feb 1, 2023
GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.
References