vendor:
tmpwatch
by:
SecurityFocus
7.5
CVSS
HIGH
Improper Handling of Arguments to System() Library Calls
78
CWE
Product Name: tmpwatch
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: YES
Related CWE: CVE-2002-0392
CPE: o:redhat:tmpwatch
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix-like systems
2002
Vulnerability in tmpwatch
An optional component of tmpwatch, fuser, improperly handles arguments to system() library calls. If an attacker creates a file with a maliciously-constructed filename including shell meta characters, and -fuser is run on this file, the attacker may be able to execute arbitrary commands, potentially compromising superuser access if tmpwatch is run with root privileges.
Mitigation:
Ensure that tmpwatch is not run with root privileges.