Vulnerability Description
LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory.
CVSS Score
6.2
MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Logwatch | Logwatch | <= 2.5 |
References
- http://list.kaybee.org/archives/logwatch-announce/2002-March/000002.html
- http://marc.info/?l=bugtraq&m=101724766216872
- http://online.securityfocus.com/archive/82/264233
- http://www.iss.net/security_center/static/8652.php
- http://www.securityfocus.com/bid/4374
- http://list.kaybee.org/archives/logwatch-announce/2002-March/000002.html
- http://marc.info/?l=bugtraq&m=101724766216872
- http://online.securityfocus.com/archive/82/264233
- http://www.iss.net/security_center/static/8652.php
- http://www.securityfocus.com/bid/4374
FAQ
What is CVE-2002-0162?
CVE-2002-0162 is a vulnerability with a CVSS score of 6.2 (MEDIUM). LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory.
How severe is CVE-2002-0162?
CVE-2002-0162 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0162?
Check the references section above for vendor advisories and patch information. Affected products include: Logwatch Logwatch.