CVE-2011-3204
Hammerhead 2.1.4 - Arbitrary File Write via Symlink Attack on Log Files
Title source: llmDescription
hammerhead.cc in Hammerhead 2.1.4 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/hammer.log (aka the HH_LOG file) or (2) the REPORT_LOG file.
References (4)
Core 4
Core References
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/08/30/7
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/08/26/9
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/49548
Various Sources x_refsource_confirm
https://launchpad.net/bugs/826679
Scores
EPSS
0.0029
EPSS Percentile
20.1%
Details
CWE
CWE-59
Status
published
Products (1)
geoff_wong/hammerhead
2.1.4
Published
Sep 06, 2011
Tracked Since
Feb 18, 2026