CVE Vulnerabilities

CVE-2002-2051

Published: Dec 31, 2002 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The processor_web plugin for ModLogAn 0.5.0 through 0.7.11, when used with the splitby option, allows local users to overwrite arbitrary files via a symlink attack on files specified as hostnames in a log file.

Affected Software

Name Vendor Start Version End Version
Modlogan Modlogan 0.5 (including) 0.5 (including)
Modlogan Modlogan 0.5.6 (including) 0.5.6 (including)
Modlogan Modlogan 0.5.7 (including) 0.5.7 (including)
Modlogan Modlogan 0.6 (including) 0.6 (including)
Modlogan Modlogan 0.7.11 (including) 0.7.11 (including)

References