CVE-2000-0829

Red Hat tmpwatch - Denial of Service via Deeply Nested Directory Creation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0829. PoCs published by zenith parsec.

AI-analyzed exploit summary This exploit demonstrates a denial-of-service (DoS) vulnerability in tmpwatch by creating a deeply nested directory structure in /tmp, causing excessive forking and system resource exhaustion. The provided C code and shell script automate the creation and testing of the directory tree to trigger the vulnerability.

Description

The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by zenith parsec · textdoslinux
https://www.exploit-db.com/exploits/20217

This exploit demonstrates a denial-of-service (DoS) vulnerability in tmpwatch by creating a deeply nested directory structure in /tmp, causing excessive forking and system resource exhaustion. The provided C code and shell script automate the creation and testing of the directory tree to trigger the vulnerability.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: tmpwatch v2.5.1 (Red Hat Linux 7.0) and v2.2 (Red Hat Linux 6.2)
No auth needed
Prerequisites: Write access to /tmp or /var/tmp · tmpwatch running via cron
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5217
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/81364
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2000-080.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1664

Scores

EPSS 0.0098
EPSS Percentile 57.7%

Details

Status published
Products (3)
redhat/linux 6.1
redhat/tmpwatch 2.2
redhat/tmpwatch 2.5.1
Published Nov 14, 2000
Tracked Since Feb 18, 2026