Impact
The vulnerability allows a local attacker to cause the d.o.o.l application to follow an unexpected symbolic link when the --devel flag is used. Because the program opens its log file without setting the O_NOFOLLOW flag, it will truncate and overwrite the target of the symlink with log data. The damage can range from corruption of user files to overwriting critical system files if the program runs with elevated privileges, providing a pathway for privilege escalation.
Affected Systems
Versions of the dool project up to 1.3.8 from the scottchiefbaker repository are affected. The impact applies to any installation where the --devel flag is enabled at runtime.
Risk and Exploitability
The CVSS score of 2 indicates low impact under normal circumstances, and the EPSS score is not available, so the known exploitation likelihood is uncertain. The issue is not listed in the CISA KEV catalog, but because it permits file alteration, a local attacker with access to the system could use it to overwrite sensitive files, especially if dool is executed with root privileges. The attack vector is local and does not require network access or elevated user rights beyond what the attacker already has on the system.
OpenCVE Enrichment