CVE-2011-3204

Hammerhead 2.1.4 - Arbitrary File Write via Symlink Attack on Log Files

Title source: llm
STIX 2.1

Description

hammerhead.cc in Hammerhead 2.1.4 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/hammer.log (aka the HH_LOG file) or (2) the REPORT_LOG file.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/08/30/7
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/08/26/9
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/49548
Various Sources x_refsource_confirm
https://launchpad.net/bugs/826679

Scores

EPSS 0.0029
EPSS Percentile 20.1%

Details

CWE
CWE-59
Status published
Products (1)
geoff_wong/hammerhead 2.1.4
Published Sep 06, 2011
Tracked Since Feb 18, 2026