Lucene search

K
cve[email protected]CVE-2004-0233
HistoryAug 18, 2004 - 4:00 a.m.

CVE-2004-0233

2004-08-1804:00:00
web.nvd.nist.gov
30
utempter
cve-2004-0233
device names
directory traversal
symlink attack
security vulnerability
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.9%

Utempter allows device names that contain … (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

Affected configurations

NVD
Node
sgipropackMatch2.4
OR
sgipropackMatch3.0
OR
utempterutempterMatch0.5.2
OR
utempterutempterMatch0.5.3
Node
slackwareslackware_linux
OR
slackwareslackware_linuxMatch9.1

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.9%