Candidate: CVE-2010-1161 PublicDate: 2010-04-16 19:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1161 http://drosenbe.blogspot.com/2010/03/nano-as-root.html http://svn.savannah.gnu.org/viewvc/trunk/nano/ChangeLog?revision=4503&root=nano&view=markup Description: Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, allows local user-assisted attackers to change the ownership of arbitrary files via vectors related to the creation of backup files. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/nano/+bug/564734 https://bugs.launchpad.net/ubuntu/+source/nano/+bug/535400 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577817 Priority: low Discovered-by: Dan Rosenberg Assigned-to: CVSS: Patches_nano: upstream_nano: released (2.2.4) dapper_nano: ignored (reached end-of-life) hardy_nano: ignored (reached end-of-life) intrepid_nano: needed (reached end-of-life) jaunty_nano: ignored (reached end-of-life) karmic_nano: ignored (reached end-of-life) lucid_nano: ignored (reached end-of-life) maverick_nano: not-affected (2.2.4-1) natty_nano: not-affected (2.2.4-1) oneiric_nano: not-affected (2.2.4-1) precise_nano: not-affected (2.2.4-1) quantal_nano: not-affected (2.2.4-1) raring_nano: not-affected (2.2.4-1) saucy_nano: not-affected (2.2.4-1) trusty_nano: not-affected (2.2.4-1) trusty/esm_nano: not-affected (2.2.4-1) utopic_nano: not-affected (2.2.4-1) vivid_nano: not-affected (2.2.4-1) devel_nano: not-affected (2.2.4-1)