CVE-2004-2698

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
31/12/2004
Last modified:
03/04/2025

Description

Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) and possibly modify arbitrary files via a symlink attack on the imwheel.pid file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:imwheel:imwheel:*:*:*:*:*:*:*:* 1.0.0pre11 (including)