SB1999092801 - Unix symbolic link (symlink) following in Linux kernel
Published: September 28, 1999
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Unix symbolic link (symlink) following (CVE-ID: CVE-1999-1352)
CWE-ID: CWE-61 - UNIX Symbolic Link (Symlink) Following
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to read and manipulate data.
mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.
Remediation
Install update from vendor's website.