Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer.
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/6095 | patch vdb entry third party advisory broken link |
http://www.heysoft.de/nt/eventlog/hsb01e.htm | patch broken link |
http://www.iss.net/security_center/static/10535.php | vdb entry patch broken link |
http://securitytracker.com/id?1005517 | patch vdb entry third party advisory broken link |