← Vulnerability feed

Vulnerability record · CVE-2001-1494 · published 31 December 2001

CVE-2001-1494: Kernel util-linux link following vulnerability

Kernel · Util Linux

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.

5.5 CVSS 3.1 Medium EPSS 0.43% · top 64.9% CWE-59 · Link following
5.5CVSS 3.1 base score, v2 2.1
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-1494 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2009-0115Christophe.varoqui multipath-tools incorrect permission assignment vulnerabilityThe Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server …EPSS 0.49%7.8CVE-2008-2812Linux kernel null pointer dereference vulnerabilityThe Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or p…EPSS 0.43%7.8CVE-2007-5830Avaya message networking improper input validation vulnerabilityUnspecified vulnerability in the administrative interface in Avaya Messaging Storage Server (MSS) 3.1 before SP1, and Message Networking (MN) 3.1, al…EPSS 1.6%7.5CVE-2016-5285Mozilla nss null pointer dereference vulnerabilityA Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_Comput…EPSS 2.3%7.5CVE-2004-1307Avaya call management system server vulnerabilityInteger overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF …EPSS 6.3%7.5CVE-2004-0494Avaya cvlan vulnerabilityMultiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions vi…EPSS 1.6%5.5CVE-2006-1058Busybox vulnerabilityBusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file usi…EPSS 0.29%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed

Source: NIST National Vulnerability Database (record CVE-2001-1494), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.