Phase:Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running.
ReferencesBUGTRAQ:Monday, January 14, 2002 NMRC Advisory: OpenFile Win32 API Log Overwriting/Rewriting | URL:http://online.securityfocus.com/archive/1/250591 | XF:iis-modify-log(7919) | URL:http://xforce.iss.net/xforce/xfdb/7919 | BID:3888 | URL:http://www.secu
Votes:Assigned (Tuesday, June 21, 2005)
Comments:None (candidate not yet proposed)
F7: