CVE Vulnerabilities

CVE-2004-0233

Published: Aug 18, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

Affected Software

NameVendorStart VersionEnd Version
PropackSgi2.4 (including)2.4 (including)
PropackSgi3.0 (including)3.0 (including)
UtempterUtempter0.5.2 (including)0.5.2 (including)
UtempterUtempter0.5.3 (including)0.5.3 (including)
Red Hat Enterprise Linux 3RedHatutempter-0:0.5.5-1.3EL.0*
Red Hat Linux 9RedHat*

References