CVE-2002-1869

Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer.
References
Link Resource
http://securitytracker.com/id?1005517 Broken Link Patch Third Party Advisory VDB Entry
http://www.heysoft.de/nt/eventlog/hsb01e.htm Broken Link Patch
http://www.iss.net/security_center/static/10535.php Broken Link Patch
http://www.securityfocus.com/bid/6095 Broken Link Patch Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:heysoft:eventsave:5.1:*:*:*:*:*:*:*
cpe:2.3:a:heysoft:eventsave:5.2:*:*:*:*:*:*:*
cpe:2.3:a:heysoft:eventsave\+:5.1:*:*:*:*:*:*:*
cpe:2.3:a:heysoft:eventsave\+:5.2:*:*:*:*:*:*:*

History

15 Feb 2024, 20:19

Type Values Removed Values Added
References (SECTRACK) http://securitytracker.com/id?1005517 - Patch (SECTRACK) http://securitytracker.com/id?1005517 - Broken Link, Patch, Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/6095 - Patch (BID) http://www.securityfocus.com/bid/6095 - Broken Link, Patch, Third Party Advisory, VDB Entry
References (CONFIRM) http://www.heysoft.de/nt/eventlog/hsb01e.htm - Patch (CONFIRM) http://www.heysoft.de/nt/eventlog/hsb01e.htm - Broken Link, Patch
References (XF) http://www.iss.net/security_center/static/10535.php - Patch (XF) http://www.iss.net/security_center/static/10535.php - Broken Link, Patch
CVSS v2 : 2.1
v3 : unknown
v2 : 2.1
v3 : 3.3
CWE NVD-CWE-Other CWE-667

Information

Published : 2002-12-31 05:00

Updated : 2024-02-28 10:24


NVD link : CVE-2002-1869

Mitre link : CVE-2002-1869

CVE.ORG link : CVE-2002-1869


JSON object : View

Products Affected

heysoft

  • eventsave\+
  • eventsave
CWE
CWE-667

Improper Locking