CVE

Id
8661  
CVE No.
CVE-2004-0233  
Status
Candidate  
Description
Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.  
Phase
Assigned (20040317)  
Votes
None (candidate not yet proposed)  
Comments