Candidate: CVE-2010-1160 PublicDate: 2010-04-16 19:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1160 http://svn.savannah.gnu.org/viewvc/trunk/nano/ChangeLog?revision=4503&root=nano&view=markup http://drosenbe.blogspot.com/2010/03/nano-as-root.html Description: GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577817 https://bugs.launchpad.net/ubuntu/+source/nano/+bug/535400 https://bugs.launchpad.net/ubuntu/+source/nano/+bug/564734 Priority: low Discovered-by: Assigned-to: CVSS: Patches_nano: upstream_nano: released (2.2.4) dapper_nano: ignored (reached end-of-life) hardy_nano: ignored (reached end-of-life) intrepid_nano: needed (reached end-of-life) jaunty_nano: ignored (reached end-of-life) karmic_nano: ignored (reached end-of-life) lucid_nano: ignored (reached end-of-life) maverick_nano: not-affected (2.2.4-1) natty_nano: not-affected (2.2.4-1) oneiric_nano: not-affected (2.2.4-1) precise_nano: not-affected (2.2.4-1) quantal_nano: not-affected (2.2.4-1) raring_nano: not-affected (2.2.4-1) saucy_nano: not-affected (2.2.4-1) trusty_nano: not-affected (2.2.4-1) trusty/esm_nano: not-affected (2.2.4-1) utopic_nano: not-affected (2.2.4-1) vivid_nano: not-affected (2.2.4-1) devel_nano: not-affected (2.2.4-1)