Vulnerability Name: | CVE-1999-1210 (CCN-613) | ||||||||
Assigned: | 1997-11-12 | ||||||||
Published: | 1997-11-12 | ||||||||
Updated: | 2017-12-19 | ||||||||
Summary: | xterm in Digital UNIX 4.0B *with* patch kit 5 allows local users to overwrite arbitrary files via a symlink attack on a core dump file, which is created when xterm is called with a DISPLAY environmental variable set to a display that xterm cannot access. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed, 12 Nov 1997 14:51:40 -0500 Digital Unix Security Problem Source: MITRE Type: CNA CVE-1999-1210 Source: BUGTRAQ Type: UNKNOWN 19971112 Digital Unix Security Problem Source: CCN Type: OSVDB ID: 8762 Digital Unix xterm DISPLAY Variable Symlink Arbitrary File Overwrite Source: XF Type: UNKNOWN dec-xterm(613) Source: XF Type: UNKNOWN dec-xterm(613) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |