2.1

CVE-2004-0233

Exploit

Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SgiPropack Version2.4
SgiPropack Version3.0
UtempterUtempter Version0.5.2
UtempterUtempter Version0.5.3
SlackwareSlackware Linux Version9.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.408
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N