vendor:
Pico
by:
SecurityFocus
7.5
CVSS
HIGH
Arbitrary File Overwrite
264
CWE
Product Name: Pico
Affected Version From: 3.8
Affected Version To: 4.3
Patch Exists: YES
Related CWE: CVE-2002-0392
CPE: a:university_of_washington:pico
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux/Unix
2002
Pico Text Editor Arbitrary File Overwrite Vulnerability
Under very specific circumstances, it is possible to cause this version of Pico to overwrite arbitrary files with the privilege level of the victim user. As a result, if the attacker is able to correctly predict the name of the editor's temporary file, the current contents of the editor can be written to key system files or other data to which the user has write privileges.
Mitigation:
Upgrade to the latest version of Pico, or use an alternative text editor.