CVE-2004-2698

imwheel < 1.0.0pre11 - Denial of Service via Symlink Attack on PID File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2698. PoCs published by I)ruid.

AI-analyzed exploit summary This exploit targets a race condition in IMWheel's predictable temporary file creation, allowing a local attacker to overwrite the PID file and potentially gain elevated privileges or cause a denial of service. The script floods the PID file with characters and then clears it, exploiting the race window.

Description

Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) and possibly modify arbitrary files via a symlink attack on the imwheel.pid file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by I)ruid · bashlocallinux
https://www.exploit-db.com/exploits/24398

This exploit targets a race condition in IMWheel's predictable temporary file creation, allowing a local attacker to overwrite the PID file and potentially gain elevated privileges or cause a denial of service. The script floods the PID file with characters and then clears it, exploiting the race window.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: IMWheel 1.0.0pre11
No auth needed
Prerequisites: Local access to the target system · IMWheel running with elevated privileges
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17082
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1011049
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12349
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11008
Various Sources x_refsource_misc
http://www.caughq.org/advisories/CAU-2004-0002.txt
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0914.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/9111

Scores

EPSS 0.0047
EPSS Percentile 36.8%

Details

CWE
CWE-362
Status published
Products (1)
imwheel/imwheel < 1.0.0pre11
Published Dec 31, 2004
Tracked Since Feb 18, 2026