CVE-2001-0300: Low severity Oracle Internet Directory vulnerability
oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0300?
CVE-2001-0300 is considered a moderate severity vulnerability due to the potential for local users to exploit file permissions.
How do I fix CVE-2001-0300?
To fix CVE-2001-0300, change the permissions of the ldaplog directory to prevent world-writable access.
What impact does CVE-2001-0300 have on system security?
CVE-2001-0300 can lead to unauthorized deletion or modification of log files, compromising the integrity of the system logs.
Which software is affected by CVE-2001-0300?
CVE-2001-0300 affects Oracle Internet Directory version 2.1.1.1.
Is there an exploit available for CVE-2001-0300?
While specific exploits may exist, the vulnerability allows for local attacks through symlink manipulation, which requires access to the filesystem.