UTempter Multiple Local Vulnerabilities

The following proof of concept has been provided to leverage the symbolic link issue:

An attacker would create the following symbolic link that references an arbitrary system file:

/tmp/tty0

The attacker would then provide the following device descriptor string to the application:

/dev/../tmp/tty0


 

Privacy Statement
Copyright 2010, SecurityFocus