First published: Fri Dec 31 1999(Updated: )
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Linux | <=5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1332 is considered to have a moderate severity due to the potential for local users to overwrite files belonging to other users.
To resolve CVE-1999-1332, upgrade to a later version of the gzip package that is not vulnerable to this symlink attack.
CVE-1999-1332 affects local users on Red Hat Linux versions 5.0 and earlier.
CVE-1999-1332 represents a symlink attack that exploits temporary file handling in the gzexe program.
No, CVE-1999-1332 requires local access to exploit, meaning it cannot be executed remotely.