PT-2001-1529 · Oracle · Oracle+1
Published
2001-04-04
·
Updated
2017-07-11
·
CVE-2001-0300
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
oidldapd version 2.1.1.1 in Oracle 8.1.7
Description
The issue allows local users to potentially delete logs or overwrite other files due to world-writable permissions in the ldaplog directory. This could be achieved through a symlink attack.
Recommendations
For oidldapd version 2.1.1.1 in Oracle 8.1.7, consider changing the permissions of the ldaplog directory to prevent world-writable access, thereby mitigating the risk of local users deleting logs or overwriting files via a symlink attack.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle
Oidldapd