First published: Wed Apr 04 2001(Updated: )
oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Internet Directory | =2.1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0300 is considered a moderate severity vulnerability due to the potential for local users to exploit file permissions.
To fix CVE-2001-0300, change the permissions of the ldaplog directory to prevent world-writable access.
CVE-2001-0300 can lead to unauthorized deletion or modification of log files, compromising the integrity of the system logs.
CVE-2001-0300 affects Oracle Internet Directory version 2.1.1.1.
While specific exploits may exist, the vulnerability allows for local attacks through symlink manipulation, which requires access to the filesystem.