CVE-1999-0732: Low severity Debian Debian Linux vulnerability

Published Aug 19, 1999
·
Updated

The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.

Affected Software

1 affected component
Debian Debian Linux=4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove debian/smtp-refuser from your environment.

    Uninstall the smtp-refuser package if it is not required to eliminate the vulnerable logging facility.

  2. Configuration

    Disable smtp-refuser's logging facility if possible. If logging must remain enabled, configure log file locations and permissions so that unprivileged local users cannot create or replace log files or create symbolic links into sensitive locations (ensure log directories and files are owned by a privileged account and are not writable by local users).

    Debian smtp-refuser logging facility = disabled or restricted
  3. Compensating control

    Restrict local user write access to the directories used for smtp-refuser logging (prevent unprivileged users from creating symlinks in those directories) and apply host-level protections (file permissions, ACLs, or mandatory access control) to prevent arbitrary file deletion via symbolic links.

Event History

Aug 19, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0732?

CVE-1999-0732 has a medium severity rating due to its potential to allow local users to delete arbitrary files.

2

How do I fix CVE-1999-0732?

To fix CVE-1999-0732, you should update the Debian smtp-refuser package to a version that addresses this vulnerability.

3

Who is affected by CVE-1999-0732?

CVE-1999-0732 affects users of the Debian GNU/Linux 4.0 operating system running the smtp-refuser package.

4

What systems are vulnerable to CVE-1999-0732?

Any system running Debian GNU/Linux version 4.0 with the smtp-refuser package installed is vulnerable to CVE-1999-0732.

5

What is the impact of CVE-1999-0732?

The impact of CVE-1999-0732 allows local users to manipulate symbolic links, potentially leading to file deletion.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203