PT-2001-1027 · Red Hat+3 · Logrotate+2
Published
2001-04-05
·
Updated
2020-04-30
·
CVE-2001-0406
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Samba versions prior to 2.2.0
logrotate version 3.5.2
Description
The issue allows local attackers to exploit a vulnerability, potentially leading to a breach of protected information integrity. This can be achieved through a symlink attack using various methods, such as a printer queue query, the more command in
smbclient, or the mput command in smbclient. The exploitation can be carried out locally.Recommendations
For Samba versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue.
For logrotate version 3.5.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Samba
Logrotate