CVE-2001-0289
Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute…
Does this matter?
Lower severity and a low EPSS score (0.74%). Track it; it rarely justifies an emergency change on its own.
Description
Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.74% probability · 53th percentile
- CISA KEV
- Not listed
- Affected
- joseph allen/joe
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-02/0490.htmlPatch, Vendor Advisory
- http://www.debian.org/security/2001/dsa-041Patch, Vendor Advisory
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-026.php3Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2001-024.html
- http://archives.neohapsis.com/archives/bugtraq/2001-02/0490.htmlPatch, Vendor Advisory
- http://www.debian.org/security/2001/dsa-041Patch, Vendor Advisory
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-026.php3Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2001-024.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.