First published: Tue Dec 31 2002(Updated: )
Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =4.0 | |
Microsoft Internet Information Services (IIS) | =5.0 | |
Symantec Norton Internet Security | =2001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1695 is considered a medium severity vulnerability due to its potential for unauthorized modification of log files.
To fix CVE-2002-1695, restrict the log file access permissions to prevent remote attackers from modifying the logs.
CVE-2002-1695 affects Norton Internet Security 2001, Microsoft Internet Information Services 5.0, and Microsoft Internet Information Server 4.0.
CVE-2002-1695 can be exploited through remote attacks that modify log files while Norton Internet Security is running.
There is no specific patch for CVE-2002-1695; users should implement changes to file permissions as a mitigation strategy.