Vulnerability Name:

CVE-1999-0730 (CCN-2279)

Assigned:1999-06-02
Published:1999-06-02
Updated:2022-08-17
Summary:The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:File Manipulation
References:Source: MITRE
Type: CNA
CVE-1999-0730

Source: CCN
Type: BugTraq Mailing List, 1999-06-02 9:01:32
/tmp symlink problems in SuSE Linux 6.1

Source: CCN
Type: BugTraq Mailing List, 1999-06-12 21:57:37
New version of man-db fixes symlink attack in zsoelim

Source: DEBIAN
Type: Debian Security Advisory 19990612
man-db: Symlink attack

Source: CCN
Type: OSVDB ID: 6204
man-db zsoelim Symlink Arbitrary File Overwrite

Source: CCN
Type: SuSE Security Announcement #07
man-2.3.10-42

Source: XF
Type: UNKNOWN
man-zsoelim(2279)

Source: MISC
Type: UNKNOWN
https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0730

Vulnerable Configuration:Configuration 1:
  • cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    debian debian linux 4.0
    linux linux kernel *
    debian debian linux *
    suse suse linux *