Vulnerability Description
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jmcce | Jmcce | 1.3.8 |
| Mandrakesoft | Mandrake Linux | 8.1 |
References
- http://www.iss.net/security_center/static/7980.phpPatch
- http://www.mandriva.com/security/advisories?name=MDKSA-2002:008
- http://www.securityfocus.com/bid/3940Patch
- http://www.iss.net/security_center/static/7980.phpPatch
- http://www.mandriva.com/security/advisories?name=MDKSA-2002:008
- http://www.securityfocus.com/bid/3940Patch
FAQ
What is CVE-2002-2001?
CVE-2002-2001 is a vulnerability with a CVSS score of 1.2 (LOW). jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
How severe is CVE-2002-2001?
CVE-2002-2001 has been rated LOW with a CVSS base score of 1.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-2001?
Check the references section above for vendor advisories and patch information. Affected products include: Jmcce Jmcce, Mandrakesoft Mandrake Linux.