CVE Vulnerabilities

CVE-2002-2051

Published: Dec 31, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The processor_web plugin for ModLogAn 0.5.0 through 0.7.11, when used with the splitby option, allows local users to overwrite arbitrary files via a symlink attack on files specified as hostnames in a log file.

Affected Software

Name Vendor Start Version End Version
Modlogan Modlogan 0.5 (including) 0.5 (including)
Modlogan Modlogan 0.5.6 (including) 0.5.6 (including)
Modlogan Modlogan 0.5.7 (including) 0.5.7 (including)
Modlogan Modlogan 0.6 (including) 0.6 (including)
Modlogan Modlogan 0.7.11 (including) 0.7.11 (including)

References