#VU100017 Unix symbolic link (symlink) following in Linux kernel - CVE-1999-1352 

 

#VU100017 Unix symbolic link (symlink) following in Linux kernel - CVE-1999-1352

Published: September 28, 1999 / Updated: October 18, 2016


Vulnerability identifier: #VU100017
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-1999-1352
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Linux kernel
Software vendor:
Linux Foundation

Description

The vulnerability allows a local user to read and manipulate data.

mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.


Remediation

Install update from vendor's repository.

External links