PT-2001-1027 · Red Hat+3 · Logrotate+2

Publicado

2001-04-05

·

Atualizado

2020-04-30

·

CVE-2001-0406

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Samba versions prior to 2.2.0 logrotate version 3.5.2
Description The issue allows local attackers to exploit a vulnerability, potentially leading to a breach of protected information integrity. This can be achieved through a symlink attack using various methods, such as a printer queue query, the more command in smbclient, or the mput command in smbclient. The exploitation can be carried out locally.
Recommendations For Samba versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue. For logrotate version 3.5.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2020-1168
ALT-PU-2020-1900
BDU:2015-07843
BDU:2015-07848
CVE-2001-0406

Produtos afetados

Alt Linux
Samba
Logrotate