CVE-2001-0625: High severity Broadcom Inoculateit vulnerability
Published Aug 22, 2001
·Updated
ftpdownload in Computer Associates InoculateIT 6.0 allows a local attacker to overwrite arbitrary files via a symlink attack on /tmp/ftpdownload.log .
Affected Software
1 affected component
Broadcom Inoculateit=6.0
Event History
Aug 22, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0625?
CVE-2001-0625 is classified as a moderate severity vulnerability due to its potential for file overwriting by local attackers.
2
How do I fix CVE-2001-0625?
To fix CVE-2001-0625, ensure that the application does not follow symlinks for sensitive files such as /tmp/ftpdownload.log.
3
Who is affected by CVE-2001-0625?
CVE-2001-0625 affects systems running Computer Associates InoculateIT version 6.0.
4
What type of attack does CVE-2001-0625 involve?
CVE-2001-0625 involves a symlink attack that allows a local attacker to overwrite arbitrary files.
5
What precautions can minimize the risk of CVE-2001-0625?
To minimize the risk of CVE-2001-0625, restrict local user permissions and segregate sensitive files from writable directories.