cve/2004/CVE-2004-0233.md
2024-05-26 14:27:05 +02:00

758 B

CVE-2004-0233

Description

Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

POC

Reference

Github

No PoCs found on GitHub currently.