PT-2000-1010 · Red Hat · Tmpwatch
Published
2000-11-08
·
Updated
2017-10-10
·
CVE-2000-0829
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat Linux tmpwatch version 2.6.2
Description
The issue concerns the tmpwatch utility in Red Hat Linux, which can be exploited locally to cause a denial of service. This can happen when a local user creates deeply nested directories in /tmp or /var/tmp/, causing the utility to fork a new process for each directory level.
Recommendations
For Red Hat Linux tmpwatch version 2.6.2, consider restricting access to the /tmp and /var/tmp directories to prevent local users from creating deeply nested directories until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tmpwatch