PT-1998-1235 · Isc · Isc Bind

Publicado

1998-04-10

·

Atualizado

2008-09-05

·

CVE-1999-1499

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ISC BIND versions 4.9 and 8.1
Description The issue allows local users to destroy files via a symlink attack on (1) named dump.db when the root kills the process with a SIGINT signal, or (2) named.stats when a SIGIOT signal is used.
Recommendations For ISC BIND version 4.9, consider restricting access to the named dump.db and named.stats files to prevent unauthorized modifications. For ISC BIND version 8.1, restrict access to the named dump.db and named.stats files to prevent unauthorized modifications.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1499

Produtos afetados

Isc Bind