3.6
CVSSv2

CVE-1999-1498

Published: 06/04/1998 Updated: 05/09/2008
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 365
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Slackware Linux 3.4 pkgtool allows local malicious user to read and write to arbitrary files via a symlink attack on the reply file.

Vulnerable Product Search on Vulmon Subscribe to Product

slackware slackware linux 3.4

Exploits

source: wwwsecurityfocuscom/bid/82/info pkgtool creates the file /tmp/reply insecurely and follows symbolic links An attacker can create a symbolic link from /tmp/reply to any file and wait for root to run the program This will clober the target file The file created has permissions -rw-rw-rw- $ cp /etc/passwd /tmp/passwd $ ln -s /tm ...