CVE-1999-0743: Low severity Debian Debian Linux vulnerability
Trn allows local users to overwrite other users' files via symlinks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
trnfrom your environment.Uninstall the Trn package from affected Debian systems until a patched version is available.
- Compensating control
Restrict local access to the Trn binary and affected systems to trusted accounts only (for example, remove execute permission for untrusted users or apply filesystem ACLs; restrict interactive logins) to prevent local users from exploiting symlink-based overwrites.
- Operational
Audit user-owned files for unexpected modifications and restore any files that were overwritten from known-good backups; investigate and remediate any instances of unauthorized file replacement.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0743?
CVE-1999-0743 is considered a moderate severity vulnerability as it allows local users to overwrite files of other users.
How do I fix CVE-1999-0743?
To fix CVE-1999-0743, ensure that symlink handling is secured and restrict local user permissions where possible.
Which software is affected by CVE-1999-0743?
CVE-1999-0743 specifically affects Debian Linux version 4.0.
Can CVE-1999-0743 be exploited remotely?
CVE-1999-0743 cannot be exploited remotely as it requires local user access to the system.
What type of vulnerability is CVE-1999-0743?
CVE-1999-0743 is a symlink vulnerability that can lead to file overwriting by local users.