CVE
- Id
- 433
- CVE No.
- CVE-1999-0434
- Status
- Candidate
- Description
- XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
- Phase
- Proposed (19990728)
- Votes
- ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Christey
- Comments
- Frech> XF:xfree86-xfs-symlink-dos | Christey> Is this the same problem as CVE-1999-0433? CVE-1999-0433 | deals with a symlink attack on one file (/tmp/.X11-unix), | while xfs (this candidate) deals with /tmp/.font-unix | XF:xfree86-xfs-symlink-dos doesn"t exist. | Christey> ADDREF DEBIAN:19990331 symbolic link can be used to make any file world readable | Note: Debian"s advisory says that this is not a problem for Debian.