CVE-1999-1495: Low severity SUSE SuSE Linux vulnerability
xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
xtvscreenfrom your environment.Uninstall xtvscreen from affected SUSE Linux systems (SUSE Linux 6.0) if it is not required to eliminate the symlink-based arbitrary file overwrite risk.
- Compensating control
Until a vendor patch is available, restrict local user access to the xtvscreen binary (for example, remove execute permission for non‑privileged users or place the binary in a directory accessible only to trusted administrators) to prevent unprivileged users from exploiting the symlink attack on pic000.pnm.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1495?
CVE-1999-1495 is a local privilege escalation vulnerability.
How do I fix CVE-1999-1495?
To fix CVE-1999-1495, upgrade to a later version of SUSE Linux that does not contain this vulnerability.
Who is affected by CVE-1999-1495?
Local users of SUSE Linux 6.0 are affected by CVE-1999-1495.
What type of attack is CVE-1999-1495?
CVE-1999-1495 involves a symlink attack allowing file overwriting.
Can CVE-1999-1495 be exploited remotely?
CVE-1999-1495 cannot be exploited remotely as it requires local access.