Tmpwatch Arbitrary Command Execution...

- AV AC AU C I A
发布: 2000-10-06
修订: 2025-04-13

A vulnerability exists in tmpwatch, a utility which automates the removal of temporary files in unix-like systems. An optional component of tmpwatch, fuser, improperly handles arguments to system() library calls. If an attacker creates a file with a maliciously-constructed filename including shell meta characters, and -fuser is run on this file, the attacker may be able to execute arbitrary commands, potentially compromising superuser access if tmpwatch is run with root privileges.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息