CVE-2004-0233
UTempter 0.5.x - Multiple Local Vulnerabilities
Severity Score
2.1
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.
Utempter permite nombres de dispositivo que contengan secuencias de cruce de directorios ".." (punto punto), lo que permite a usuarios locles sobreesciribir ficheros de su elección mediante un ataque de enlaces simbólicos en nombres de dispositivos en combinación con una aplicación que confíe en ficheros utmp o wtmp.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-03-17 CVE Reserved
- 2004-04-19 CVE Published
- 2004-04-19 First Exploit
- 2023-03-08 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (13)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/24027 | 2004-04-19 | |
http://www.securityfocus.com/bid/10178 | 2024-08-08 |
URL | Date | SRC |
---|---|---|
http://www.redhat.com/support/errata/RHSA-2004-174.html | 2017-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sgi Search vendor "Sgi" | Propack Search vendor "Sgi" for product "Propack" | 2.4 Search vendor "Sgi" for product "Propack" and version "2.4" | - |
Affected
| ||||||
Sgi Search vendor "Sgi" | Propack Search vendor "Sgi" for product "Propack" | 3.0 Search vendor "Sgi" for product "Propack" and version "3.0" | - |
Affected
| ||||||
Utempter Search vendor "Utempter" | Utempter Search vendor "Utempter" for product "Utempter" | 0.5.2 Search vendor "Utempter" for product "Utempter" and version "0.5.2" | - |
Affected
| ||||||
Utempter Search vendor "Utempter" | Utempter Search vendor "Utempter" for product "Utempter" | 0.5.3 Search vendor "Utempter" for product "Utempter" and version "0.5.3" | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | * | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | 9.1 Search vendor "Slackware" for product "Slackware Linux" and version "9.1" | - |
Affected
|