3238Third-party advisory
http://securityreason.com/securityalert/3238 CVE-2003-1366
OpenBSD 2.x/3.x - CHPass Temporary File Link File Content Revealing
Record summary
CVE-2003-1366 has a selected CVSS score of 3.3; EIP currently links 1 catalogued exploit.
Description
chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenBSD 2.x/3.x - CHPass Temporary File Link File Content RevealingExploitDB exploitby Marc BevandNot analyzed1 file
References
7epita.fr
http://www.epita.fr/~bevand_m/asa/asa-0001 20030203 ASA-0001: OpenBSD chpass/chfn/chsh file content leakmailing list
http://www.securityfocus.com/archive/1/309962 6748vdb entry
http://www.securityfocus.com/bid/6748 1006035vdb entry
http://www.securitytracker.com/id?1006035 openbsd-chpass-information-disclosure(11233)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/11233 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-1366