[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256610

 
 

909

 
 

199263

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-0233Date: (C)2004-08-18   (M)2023-12-22


Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.1
Exploit Score: 3.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SUNALERT-1000752
BID-10178
GLSA-200405-05
MDKSA-2004:031
RHSA-2004:174
RHSA-2004:175
SSA:2004-110
oval:org.mitre.oval:def:10115
oval:org.mitre.oval:def:979
utemper-symlink(15904)

CPE    3
cpe:/o:slackware:slackware_linux:9.1
cpe:/a:sgi:propack:2.4
cpe:/a:sgi:propack:3.0

© SecPod Technologies