CVE-1999-0689: High severity CDE CDE vulnerability
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
CDE dtspcd daemonfrom your environment.Uninstall or remove the dtspcd daemon if it is not required for operations.
- Configuration
Stop and disable the dtspcd daemon on affected systems to prevent exploitation (do not run dtspcd until a vendor fix is available).
CDE dtspcd daemon service_enabled = false - Compensating control
Restrict local unprivileged user access until the issue is fixed: disable or remove untrusted local accounts, restrict interactive logins, and tighten filesystem and IPC permissions to prevent untrusted users from performing symlink attacks against dtspcd.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0689?
CVE-1999-0689 is categorized as a local privilege escalation vulnerability.
How do I fix CVE-1999-0689?
To fix CVE-1999-0689, it is recommended to update to a patched version of CDE that addresses this issue.
What software is affected by CVE-1999-0689?
CVE-1999-0689 affects multiple versions of the CDE dtspcd daemon including 1.0.1, 1.0.2, 1.1, and 2.1.
How does CVE-1999-0689 exploit work?
CVE-1999-0689 exploits a symlink attack that allows local users to execute arbitrary commands.
Is there a workaround for CVE-1999-0689?
A potential workaround for CVE-1999-0689 is to restrict access to the dtspcd daemon or disable it entirely if not needed.