First published: Tue Dec 31 2002(Updated: )
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
jmcce jmcce | =1.3.8 | |
Mandrake Linux | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2001 is considered a medium severity vulnerability due to the potential for local file overwriting through a symlink attack.
To fix CVE-2002-2001, you should update jmcce to a version that does not create predictable log file names.
Users of jmcce version 1.3.8 on Mandrake Linux 8.1 are primarily affected by CVE-2002-2001.
CVE-2002-2001 enables local users to conduct a symlink attack to overwrite arbitrary files.
CVE-2002-2001 was disclosed in the year 2002.