2.1
CVSSv2

CVE-1999-0857

Published: 01/12/1999 Updated: 09/09/2008
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

FreeBSD gdc program allows local users to modify files via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 3.3

Exploits

source: wwwsecurityfocuscom/bid/835/info It is possible to write debug ouput from gdc to a file (/var/tmp/gdb_dump) Unfortunately, gdc follows symbolic links which can be created in tmp and will overwrite any file on the system thanks to it being setiud root This does not cause any immediate compromises and is more of a denial of servic ...