PT-2012-4726 · Logol · Logol
Andreas Beckmann
·
Published
2012-08-07
·
Updated
2012-08-08
·
CVE-2012-3453
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
logol version 1.5.0
Description
The issue allows local users to delete or overwrite arbitrary files due to world writable permissions for the /var/lib/logol/results directory.
Recommendations
For logol version 1.5.0, consider changing the permissions of the /var/lib/logol/results directory to prevent world writability as a temporary workaround until a patch is available. Restrict access to the /var/lib/logol/results directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Logol