PT-1998-1234 · Slackware · Slackware Linux

Publicado

1998-04-06

·

Atualizado

2008-09-05

·

CVE-1999-1498

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Slackware Linux version 3.4
Description The issue allows a local attacker to read and write to arbitrary files via a symlink attack on the reply file. This is related to the pkgtool in Slackware Linux.
Recommendations For Slackware Linux version 3.4, consider restricting access to the pkgtool until a fix is available, and avoid using it for sensitive operations to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1498

Produtos afetados

Slackware Linux