← Vulnerability feed

Vulnerability record · CVE-2000-1134 · published 9 January 2001

CVE-2000-1134: Immunix vulnerability

Immunix · Immunix

Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

7.2 CVSS 2.0 High EPSS 1.4% · top 28.3%
7.2CVSS 2.0 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
38References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:76.tcsh-csh.asc PatchVendor Advisory
ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P
http://archives.neohapsis.com/archives/bugtraq/2000-10/0418.html
http://archives.neohapsis.com/archives/tru64/2002-q1/0009.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000350
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000354
http://marc.info/?l=bugtraq&m=97561816504170&w=2
http://www.calderasystems.com/support/security/advisories/CSSA-2000-042.0.txt
http://www.calderasystems.com/support/security/advisories/CSSA-2000-043.0.txt
http://www.debian.org/security/2000/20001111a
http://www.kb.cert.org/vuls/id/10277 US Government Resource
http://www.linux-mandrake.com/en/security/MDKSA-2000-069.php3
http://www.linux-mandrake.com/en/security/MDKSA-2000-075.php3
http://www.redhat.com/support/errata/RHSA-2000-117.html
http://www.redhat.com/support/errata/RHSA-2000-121.html
http://www.securityfocus.com/archive/1/146657
http://www.securityfocus.com/bid/1926
http://www.securityfocus.com/bid/2006 ExploitPatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4047
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:76.tcsh-csh.asc PatchVendor Advisory
ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P
http://archives.neohapsis.com/archives/bugtraq/2000-10/0418.html
http://archives.neohapsis.com/archives/tru64/2002-q1/0009.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000350
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000354
http://marc.info/?l=bugtraq&m=97561816504170&w=2
http://www.calderasystems.com/support/security/advisories/CSSA-2000-042.0.txt
http://www.calderasystems.com/support/security/advisories/CSSA-2000-043.0.txt
http://www.debian.org/security/2000/20001111a
http://www.kb.cert.org/vuls/id/10277 US Government Resource
http://www.linux-mandrake.com/en/security/MDKSA-2000-069.php3
http://www.linux-mandrake.com/en/security/MDKSA-2000-075.php3
http://www.redhat.com/support/errata/RHSA-2000-117.html
http://www.redhat.com/support/errata/RHSA-2000-121.html
http://www.securityfocus.com/archive/1/146657
http://www.securityfocus.com/bid/1926
http://www.securityfocus.com/bid/2006 ExploitPatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4047

Track CVE-2000-1134 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed10.0CVE-2012-0131Hp distributed computing environment vulnerabilityDistributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly …EPSS 7.4%10.0CVE-2008-1668Hp-ux permissions and access controls vulnerabilityftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which P…EPSS 4.5%10.0CVE-2008-1662Hp-ux vulnerabilityUnspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allow remote …EPSS 4.4%10.0CVE-2007-6425Hp-ux memory buffer overflow vulnerabilityUnspecified vulnerability in HP-UX B.11.31, when running ARPA Transport, allows remote attackers to cause a denial of service via unknown vectors.EPSS 4.3%10.0CVE-2007-6195Hp-ux memory buffer overflow vulnerabilityBuffer overflow in the sw_rpc_agent_init function in swagentd in Software Distributor (SD), and possibly other DCE applications, in HP HP-UX B.11.11 …EPSS 14%10.0CVE-2007-4241Hp-ux vulnerabilityBuffer overflow in ldcconn in Hewlett-Packard (HP) Controller for Cisco Local Director on HP-UX 11.11i allows remote attackers to execute arbitrary c…EPSS 11%10.0CVE-2007-0915Hp-ux vulnerabilityDistributed SLS daemon (SLSd) on HP-UX B.11.11 allows remote attackers to overwrite arbitrary files and gain privileges via a crafted RPC request.EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2000-1134), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.