Security Advisory

CVE-2004-0233

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2004-05-05 04:00:00
Last updated 2024-08-08 00:10:03
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.