2.1

CVE-2004-0233

Exploit

Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

Data is provided by the National Vulnerability Database (NVD)
SgiPropack Version2.4
SgiPropack Version3.0
UtempterUtempter Version0.5.2
UtempterUtempter Version0.5.3
SlackwareSlackware Linux Version9.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.21% 0.408
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N