CVE-2000-0366: Low severity Debian Debian Linux vulnerability

Published Dec 2, 1999
·
Updated

dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.

Affected Software

1 affected component
Debian Debian Linux=2.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove debian/dump from your environment.

    If dump is not required, uninstall the dump package or remove the dump binary from systems running Debian GNU/Linux 2.1 to eliminate the vulnerable component.

  2. Configuration

    Restrict execution of the dump binary to privileged administrators only (for example: chown root:root /usr/sbin/dump; chmod 700 /usr/sbin/dump) or otherwise ensure only trusted accounts can run dump.

    dump (Debian GNU/Linux 2.1) executable permission / allowed users = root-only
  3. Compensating control

    Restrict local user access to backup devices, backup files, and restoration facilities using filesystem permissions and local ACLs or sudoers entries so untrusted local users cannot perform restore operations.

  4. Operational

    Audit the filesystem for files with unexpected ownership changes and restore correct ownerships from known-good backups; review recent restore operations to identify any unauthorized ownership modifications.

Event History

Dec 2, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0366?

CVE-2000-0366 is categorized as a moderate severity vulnerability due to its potential to allow local users to modify file ownership.

2

How do I fix CVE-2000-0366?

To address CVE-2000-0366, update your Debian GNU/Linux system to a version that properly restores symlinks.

3

What software is affected by CVE-2000-0366?

CVE-2000-0366 specifically affects Debian GNU/Linux version 2.1.

4

Who can exploit CVE-2000-0366?

CVE-2000-0366 can be exploited by local users with access to the system.

5

What are the potential impacts of CVE-2000-0366?

The potential impact of CVE-2000-0366 includes unauthorized modification of file ownership, which can lead to privilege escalation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203