CVE-2004-0233: Low severity sgi propack vulnerability
Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0233?
CVE-2004-0233 is classified as a high severity vulnerability due to its potential for local users to compromise system files.
How do I fix CVE-2004-0233?
To fix CVE-2004-0233, update Utempter to version 0.5.4 or later and ensure device names are properly validated.
Who is affected by CVE-2004-0233?
CVE-2004-0233 affects systems using Utempter versions 0.5.2 and 0.5.3 and certain versions of SGI ProPack.
What can an attacker do with CVE-2004-0233?
An attacker can exploit CVE-2004-0233 to overwrite arbitrary files on the system using a symlink attack.
Is CVE-2004-0233 a remote or local vulnerability?
CVE-2004-0233 is a local vulnerability, requiring local access to the system to exploit.