GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.
CVSS Details
- CVSS 3.1 Base Score: 3.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nano | Jul 30, 2024 | Apr 16, 2010 |
| Gentoo Linux | — | Upgrade app-editors/nano. | Oct 30, 2017 | Apr 16, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 2, 2010 |
| Suse | — | Upgrade nanoUpgrade nano-lang | Aug 9, 2024 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub