PT-2000-1010 · Red Hat · Tmpwatch

Publicado

2000-11-08

·

Atualizado

2017-10-10

·

CVE-2000-0829

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Red Hat Linux tmpwatch version 2.6.2
Description The issue concerns the tmpwatch utility in Red Hat Linux, which can be exploited locally to cause a denial of service. This can happen when a local user creates deeply nested directories in /tmp or /var/tmp/, causing the utility to fork a new process for each directory level.
Recommendations For Red Hat Linux tmpwatch version 2.6.2, consider restricting access to the /tmp and /var/tmp directories to prevent local users from creating deeply nested directories until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07927
CVE-2000-0829

Produtos afetados

Tmpwatch