Lucene search

K
cveMitreCVE-2000-0336
HistoryJul 12, 2000 - 4:00 a.m.

CVE-2000-0336

2000-07-1204:00:00
mitre
web.nvd.nist.gov
32
linux
openldap server
local user
file modification
symlink attack
cve-2000-0336

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

0.4%

Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.

Affected configurations

Nvd
Node
openldapopenldapMatch1.2.7
OR
openldapopenldapMatch1.2.8
OR
openldapopenldapMatch1.2.9
OR
openldapopenldapMatch1.2.10
Node
mandrakesoftmandrake_linuxMatch6.1
OR
mandrakesoftmandrake_linuxMatch7.0
OR
redhatlinuxMatch6.1alpha
OR
redhatlinuxMatch6.1i386
OR
redhatlinuxMatch6.1sparc
OR
redhatlinuxMatch6.2alpha
OR
redhatlinuxMatch6.2i386
OR
redhatlinuxMatch6.2sparc
OR
turbolinuxturbolinuxMatch4.2
OR
turbolinuxturbolinuxMatch4.4
OR
turbolinuxturbolinuxMatch6.0.2
VendorProductVersionCPE
openldapopenldap1.2.7cpe:2.3:a:openldap:openldap:1.2.7:*:*:*:*:*:*:*
openldapopenldap1.2.8cpe:2.3:a:openldap:openldap:1.2.8:*:*:*:*:*:*:*
openldapopenldap1.2.9cpe:2.3:a:openldap:openldap:1.2.9:*:*:*:*:*:*:*
openldapopenldap1.2.10cpe:2.3:a:openldap:openldap:1.2.10:*:*:*:*:*:*:*
mandrakesoftmandrake_linux6.1cpe:2.3:o:mandrakesoft:mandrake_linux:6.1:*:*:*:*:*:*:*
mandrakesoftmandrake_linux7.0cpe:2.3:o:mandrakesoft:mandrake_linux:7.0:*:*:*:*:*:*:*
redhatlinux6.1cpe:2.3:o:redhat:linux:6.1:*:alpha:*:*:*:*:*
redhatlinux6.1cpe:2.3:o:redhat:linux:6.1:*:i386:*:*:*:*:*
redhatlinux6.1cpe:2.3:o:redhat:linux:6.1:*:sparc:*:*:*:*:*
redhatlinux6.2cpe:2.3:o:redhat:linux:6.2:*:alpha:*:*:*:*:*
Rows per page:
1-10 of 151

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

0.4%

Related for CVE-2000-0336