CVE
- Id
- 3121
- CVE No.
- CVE-2001-0300
- Status
- Candidate
- Description
- oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.
- Phase
- Modified (20050509)
- Votes
- NOOP(3) Cole, Wall, Ziese | REJECT(1) Frech | REVIEWING(1) Bishop
- Comments
- Frech> Validity threshold is not met by the references cited. Would | be willing to reassess and change vote if more information is | forthcoming.