First published: Wed Nov 12 1997(Updated: )
xterm in Digital UNIX 4.0B *with* patch kit 5 allows local users to overwrite arbitrary files via a symlink attack on a core dump file, which is created when xterm is called with a DISPLAY environmental variable set to a display that xterm cannot access.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Digital OpenVMS | =4.0b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1210 is considered a moderate severity vulnerability due to the potential for local users to exploit it.
To fix CVE-1999-1210, ensure that core dump file handling is secured to prevent symlink attacks.
CVE-1999-1210 affects local users of Digital UNIX 4.0B with patch kit 5.
CVE-1999-1210 involves a symlink attack that allows overwriting of arbitrary files.
CVE-1999-1210 is triggered when xterm is called with an inaccessible DISPLAY environment variable.