PT-2000-1009 · Red Hat · Tmpwatch
Published
2000-10-06
·
Updated
2017-10-10
·
CVE-2000-0816
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
tmpwatch version 2.6.2
Description
The issue concerns multiple vulnerabilities in the tmpwatch package of Red Hat Linux, which can lead to disruption of protected information availability. These vulnerabilities can be exploited locally. Specifically, the
--fuser option in Linux tmpwatch allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.Recommendations
For tmpwatch version 2.6.2, consider restricting access to the
--fuser option to prevent local users from executing arbitrary commands until a patch is available. As a temporary workaround, avoid using the --fuser option in tmpwatch to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tmpwatch