2.1
CVSSv2

CVE-2000-0293

Published: 02/05/2000 Updated: 10/09/2008
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory.

Vulnerable Product Search on Vulmon Subscribe to Product

suse suse linux 6.1

suse suse linux 6.2

suse suse linux 6.3

suse suse linux 6.0

suse suse linux 6.4

Exploits

source: wwwsecurityfocuscom/bid/1130/info A vulnerability exists in SuSE Linux, version 63 and prior, that can allow arbitrary users to delete any file on the system If the MAX_DAYS_IN_TMP variable is set in /etc/rcconfig to be larger than 0, any local user can remove any file on the system This is due to a flaw in /etc/crondaily/aaa ...