CVE Vulnerabilities

CVE-2004-0233

Published: Aug 18, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

Affected Software

Name Vendor Start Version End Version
Propack Sgi 2.4 2.4
Propack Sgi 3.0 3.0
Utempter Utempter 0.5.2 0.5.2
Utempter Utempter 0.5.3 0.5.3
Red Hat Enterprise Linux 3 RedHat utempter-0:0.5.5-1.3EL.0 *
Red Hat Linux 9 RedHat utempter *

References