2.1
CVSSv2

CVE-1999-1499

Published: 10/04/1998 Updated: 05/09/2008
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used.

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind 4.9

isc bind 8.1

Exploits

source: wwwsecurityfocuscom/bid/80/info The named daemon will dump the named database to /var/tmp/named_dumpdb when it receives a SIGINT signal It does not check for symbolic links while doing so and can be made to overwrite any file in the system The named daemons will append named statistics to /var/tmp/namedstats when it receives ...