PT-2000-1010 · Red Hat · Tmpwatch

Published

2000-11-08

·

Updated

2017-10-10

·

CVE-2000-0829

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Red Hat Linux tmpwatch version 2.6.2
Description The issue concerns the tmpwatch utility in Red Hat Linux, which can be exploited locally to cause a denial of service. This can happen when a local user creates deeply nested directories in /tmp or /var/tmp/, causing the utility to fork a new process for each directory level.
Recommendations For Red Hat Linux tmpwatch version 2.6.2, consider restricting access to the /tmp and /var/tmp directories to prevent local users from creating deeply nested directories until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07927
CVE-2000-0829

Affected Products

Tmpwatch