Search

published date: December 31, 2002

CVE-2002-2051 : The processor_web plugin for...

Description

The processor_web plugin for ModLogAn 0.5.0 through 0.7.11, when used with the splitby option, allows local users to overwrite arbitrary files via a symlink attack on files specified as hostnames in a log file.

Product(s):

  • Modlogan Modlogan 0.5.6
  • Modlogan Modlogan 0.5.7
  • Modlogan Modlogan 0.5
  • Modlogan 0.6
  • Modlogan 0.7.11

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2002-2051, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2002-2051 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?