MDKSA-2000:056Vendor advisory
http://www.linux-mandrake.com/en/security/MDKSA-2000-056.php3?dis=7.1 CVE-2000-0816
RedHat 6.2/7.0 Tmpwatch - Arbitrary Command Execution
Record summary
CVE-2000-0816 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRedHat 6.2/7.0 Tmpwatch - Arbitrary Command ExecutionExploitDB exploitby X-ForceNot analyzed1 file
References
6RHSA-2000:080Vendor advisory
http://www.redhat.com/support/errata/RHSA-2000-080.html 1785vdb entry
http://www.securityfocus.com/bid/1785 20001006 Insecure call of external programs in Red Hat Linux tmpwatchThird-party advisory
http://xforce.iss.net/alerts/advise64.php linux-tmpwatch-fuser(5320)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5320 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0816