PoC Index

CVE-2004-0233

LOW 2.1EPSS 1.1%

Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

CVSS v2.0
2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.09% chance of exploitation in the next 30 days, 63th percentile
Published
2004-05-05
Updated
2024-08-08

ExploitDB entries (1)

References

Related