2.1
CVSSv2

CVE-1999-1332

Published: 31/12/1999 Updated: 18/10/2016
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

gzexe in the gzip package on Red Hat Linux 5.0 and previous versions allows local users to overwrite files of other users via a symlink attack on a temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat linux

Vendor Advisories

Paul Szabo discovered that znew, a script included in the gzip package, creates its temporary files without taking precautions to avoid a symlink attack (CAN-2003-0367) The gzexe script has a similar vulnerability which was patched in an earlier release but inadvertently reverted For the stable distribution (woody) both problems have been fixed i ...