2.1
CVSSv2

CVE-2000-0691

Published: 20/10/2000 Updated: 05/09/2008
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.

Vulnerable Product Search on Vulmon Subscribe to Product

gert doering mgetty 1.1.19

gert doering mgetty 1.1.21

gert doering mgetty 1.1.20

Exploits

source: wwwsecurityfocuscom/bid/1612/info A vulnerability exists in a portion of the mgetty package, by Gert Doering By exploiting a flaw in the faxrunq and faxrunqd programs, it is possible for local users to create arbitrary files, and alter arbitrary files on the filesystem This in turn can lead to local root compromise The faxrunq ...