Vulnerabilities > CVE-2005-0019 - Local Arbitrary Command Execution vulnerability in Yongguang Zhang Hztty 2.0

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
yongguang-zhang
nessus

Summary

Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.

Vulnerable Configurations

Part Description Count
Application
Yongguang_Zhang
1

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-675.NASL
descriptionErik Sjolund discovered that hztty, a converter for GB, Big5 and zW/HZ Chinese encodings in a tty session, can be triggered to execute arbitrary commands with group utmp privileges.
last seen2020-06-01
modified2020-06-02
plugin id16365
published2005-02-10
reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/16365
titleDebian DSA-675-1 : hztty - privilege escalation