PT-2000-1009 · Red Hat · Tmpwatch
Publicado
2000-10-06
·
Atualizado
2017-10-10
·
CVE-2000-0816
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
tmpwatch version 2.6.2
Description
The issue concerns multiple vulnerabilities in the tmpwatch package of Red Hat Linux, which can lead to disruption of protected information availability. These vulnerabilities can be exploited locally. Specifically, the
--fuser option in Linux tmpwatch allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.Recommendations
For tmpwatch version 2.6.2, consider restricting access to the
--fuser option to prevent local users from executing arbitrary commands until a patch is available. As a temporary workaround, avoid using the --fuser option in tmpwatch to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tmpwatch