PT-2026-82539 · Dool · Dool
CVSS v4.0
2.0
Low
| Vector | AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Dool versions prior to 1.3.9
Description
The application is susceptible to symlink following when the
--devel flag is active. This occurs because the software opens a log file without the O NOFOLLOW flag, which is a system-level instruction that prevents the application from following symbolic links. A local attacker can create a symlink at the expected log file path that points to a sensitive file, leading the application to truncate and overwrite the target file with log data. This impact is increased if the application is executed with elevated privileges.Recommendations
Update to version 1.3.9 or later.
As a temporary mitigation, avoid using the
--devel flag.Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dool