10
CVSSv2

CVE-1999-0730

Published: 12/06/1999 Updated: 17/08/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 4.0

Exploits

source: wwwsecurityfocuscom/bid/305/info The man command created a temporary file under /tmp with a predictable name and is willing to follow symbolic links This may allow malicious local users to create arbitrarily named files zsoelim(1) is a utility part of the man package which prepocess man pages and satisfy so requests in roff in ...