list.kaybee.orgConfirmation
http://list.kaybee.org/archives/logwatch-announce/2002-March/000002.html CVE-2002-0162
LogWatch 2.1.1/2.5 - Insecure Temporary Directory Creation
Record summary
CVE-2002-0162 has a selected CVSS score of 6.2; EIP currently links 1 catalogued exploit.
Description
LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLogWatch 2.1.1/2.5 - Insecure Temporary Directory CreationExploitDB exploitby spybreakNot analyzed1 file
References
620020327 Root compromise through LogWatch 2.1.1mailing list
http://marc.info/?l=bugtraq&m=101724766216872 20020327 Root compromise through LogWatch 2.1.1mailing list
http://online.securityfocus.com/archive/82/264233 logwatch-tmp-race-condition(8652)vdb entry
http://www.iss.net/security_center/static/8652.php 4374vdb entry
http://www.securityfocus.com/bid/4374 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0162