PT-1999-1653 · Red Hat · Gzip
Published
1999-12-31
·
Updated
2016-10-18
·
CVE-1999-1332
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
gzip versions prior to the version on Red Hat Linux 5.0
Description:
The issue allows local users to overwrite files of other users via a symlink attack on a temporary file. This is related to the gzexe component in the gzip package.
Recommendations:
For versions prior to the version on Red Hat Linux 5.0, consider restricting access to the gzexe component to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gzip