PT-2001-1027 · Red Hat+3 · Logrotate+2

Published

2001-04-05

·

Updated

2020-04-30

·

CVE-2001-0406

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Samba versions prior to 2.2.0 logrotate version 3.5.2
Description The issue allows local attackers to exploit a vulnerability, potentially leading to a breach of protected information integrity. This can be achieved through a symlink attack using various methods, such as a printer queue query, the more command in smbclient, or the mput command in smbclient. The exploitation can be carried out locally.
Recommendations For Samba versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue. For logrotate version 3.5.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2020-1168
ALT-PU-2020-1900
BDU:2015-07843
BDU:2015-07848
CVE-2001-0406

Affected Products

Alt Linux
Samba
Logrotate