CVE-1999-0730: Critical severity Debian Debian Linux vulnerability
The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
debian/man-db (zsoelim)from your environment.Uninstall the man-db package or remove the zsoelim program if it is not required to eliminate the vulnerable binary from the system.
- Compensating control
Until a vendor fix is available, restrict access to the zsoelim program so unprivileged/local users cannot execute it (for example, remove execute permissions for non-admin users or otherwise limit which accounts can run the binary).
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0730?
CVE-1999-0730 is considered a medium severity vulnerability.
How do I fix CVE-1999-0730?
To fix CVE-1999-0730, you should update the man-db package to a patched version provided by the Debian maintainers.
Who is affected by CVE-1999-0730?
Local users on systems running the Debian man-db package version 4.0 are affected by CVE-1999-0730.
What is the nature of the vulnerability in CVE-1999-0730?
CVE-1999-0730 allows local users to overwrite files through a symlink attack.
Is CVE-1999-0730 a remote or local vulnerability?
CVE-1999-0730 is a local vulnerability, meaning it can only be exploited by users with access to the affected system.