20000826 Advisory: mgetty local compromisemailing list
http://archives.neohapsis.com/archives/bugtraq/2000-08/0329.html CVE-2000-0691
Gert Doering mgetty 1.1.19/1.1.20/1.1.21/1.22.8 - Symbolic Link Traversal
Record summary
CVE-2000-0691 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGert Doering mgetty 1.1.19/1.1.20/1.1.21/1.22.8 - Symbolic Link TraversalExploitDB exploitby Stan BubrouskiNot analyzed1 file
References
5archives.neohapsis.comConfirmation
http://archives.neohapsis.com/archives/bugtraq/2000-08/0330.html CSSA-2000-029.0Vendor advisory
http://www.calderasystems.com/support/security/advisories/CSSA-2000-029.0.txt 1612vdb entry
http://www.securityfocus.com/bid/1612 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0691