PT-1999-1653 · Red Hat · Gzip

Published

1999-12-31

·

Updated

2016-10-18

·

CVE-1999-1332

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: gzip versions prior to the version on Red Hat Linux 5.0
Description: The issue allows local users to overwrite files of other users via a symlink attack on a temporary file. This is related to the gzexe component in the gzip package.
Recommendations: For versions prior to the version on Red Hat Linux 5.0, consider restricting access to the gzexe component to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1332
DSA-308

Affected Products

Gzip