Oval Definition:oval:com.redhat.rhsa:def:20040174
Revision Date:2004-05-26Version:502
Title:RHSA-2004:174: utempter security update (Moderate)
Description:Utempter is a utility that allows terminal applications such as xterm and screen to update utmp and wtmp without requiring root privileges.

Steve Grubb discovered a flaw in Utempter which allowed device names containing directory traversal sequences such as '/../'. In combination with an application that trusts the utmp or wtmp files, this could allow a local attacker the ability to overwrite privileged files using a symlink.

Users should upgrade to this new version of utempter, which fixes this vulnerability.
Family:unixClass:patch
Status:Reference(s):CVE-2004-0233
RHSA-2004:174-01
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND utempter is earlier than 0:0.5.5-1.3EL.0
  • AND utempter is signed with Red Hat master key
  • BACK