Vulnerability Description
oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Internet Directory | 2.1.1.1 |
References
- http://archives.neohapsis.com/archives/bugtraq/2000-12/0434.htmlPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/610904US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5804
- http://archives.neohapsis.com/archives/bugtraq/2000-12/0434.htmlPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/610904US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5804
FAQ
What is CVE-2001-0300?
CVE-2001-0300 is a vulnerability with a CVSS score of 2.1 (LOW). oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink a...
How severe is CVE-2001-0300?
CVE-2001-0300 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0300?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Internet Directory.