CVE

Id
433  
CVE No.
CVE-1999-0434  
Status
Candidate  
Description
XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.  
Phase
Proposed (19990728)  
Votes
ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Christey  
Comments
Frech> XF:xfree86-xfs-symlink-dos | Christey> Is this the same problem as CVE-1999-0433? CVE-1999-0433 | deals with a symlink attack on one file (/tmp/.X11-unix), | while xfs (this candidate) deals with /tmp/.font-unix | XF:xfree86-xfs-symlink-dos doesn"t exist. | Christey> ADDREF DEBIAN:19990331 symbolic link can be used to make any file world readable | Note: Debian"s advisory says that this is not a problem for Debian.