CVE
- Id
- 1479
- CVE No.
- CVE-1999-1499
- Status
- Candidate
- Description
- named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used.
- Phase
- Proposed (20010912)
- Votes
- MODIFY(1) Frech | NOOP(2) Cole, Wall | REJECT(1) Foat
- Comments
- Foat> The files get written to /var/named which the user does not have write | access. | Frech> XF:bind-sigint-sigiot-symlink(7366)