CVE-1999-0374: Low severity Debian Debian Linux vulnerability
Debian GNU/Linux cfengine package is susceptible to a symlink attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
debian/cfenginefrom your environment.If cfengine is not required, uninstall the debian cfengine package to remove the vulnerable component.
- Operational
There are no fixed versions listed. Monitor Debian security advisories and vendor updates for a patched cfengine package and apply the vendor-provided update or patch as soon as it becomes available. Test the update before deploying to production.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0374?
The severity of CVE-1999-0374 is classified as moderate due to its potential for a symlink attack.
How do I fix CVE-1999-0374?
To fix CVE-1999-0374, update the cfengine package to the latest version available in the Debian repository.
Which systems are affected by CVE-1999-0374?
CVE-1999-0374 affects Debian GNU/Linux version 2.0.
What type of attack does CVE-1999-0374 involve?
CVE-1999-0374 involves a symlink attack that can exploit vulnerabilities in file handling.
Can CVE-1999-0374 be exploited remotely?
Yes, CVE-1999-0374 can be exploited remotely if an attacker has access to the file system.