#VU100017 Unix symbolic link (symlink) following in Linux kernel - CVE-1999-1352
Published: September 28, 1999 / Updated: October 18, 2016
Vulnerability identifier: #VU100017
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-1999-1352
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to read and manipulate data.
mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.
Remediation
Install update from vendor's repository.