CVE-1999-1332: Low severity redhat Linux vulnerability
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
gzip/gzexefrom your environment.Uninstall gzexe (the gzexe utility in the gzip package) from Red Hat Linux 5.0 and earlier or disable its execution until a vendor-supplied fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1332?
CVE-1999-1332 is considered to have a moderate severity due to the potential for local users to overwrite files belonging to other users.
How do I fix CVE-1999-1332?
To resolve CVE-1999-1332, upgrade to a later version of the gzip package that is not vulnerable to this symlink attack.
Who is affected by CVE-1999-1332?
CVE-1999-1332 affects local users on Red Hat Linux versions 5.0 and earlier.
What type of attack does CVE-1999-1332 represent?
CVE-1999-1332 represents a symlink attack that exploits temporary file handling in the gzexe program.
Can CVE-1999-1332 be exploited remotely?
No, CVE-1999-1332 requires local access to exploit, meaning it cannot be executed remotely.