PT-1999-1882 · Debian · Debian
Published
1999-12-02
·
Updated
2008-09-10
·
CVE-2000-0366
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Debian GNU/Linux version 2.1
Description
The issue is related to the dump utility in Debian GNU/Linux, which does not properly restore symlinks. This allows a local user to modify the ownership of arbitrary files.
Recommendations
For Debian GNU/Linux version 2.1, update the dump utility to a version that properly restores symlinks to prevent local users from modifying the ownership of arbitrary files.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian