Junglewise Threat Intelligence

CVE-1999-0123: Linux mailx race condition in file handling

CVE-1999-0123 · Severity: low · CVSS 3.7 · Published 1995-12-01

Technologies: Slackware Linux. Vendors: Linux, Slackware.

Executive brief

A vulnerability exists in the mailx utility, a standard command-line tool used for sending and receiving email on Linux systems. A local attacker could exploit a timing flaw to gain unauthorized access to files belonging to other users on the same system. This could lead to the exposure of sensitive personal or system information.

Technical details

A race condition exists in the Linux mailx command. By exploiting a window of time during file operations, a local authenticated user can perform a symlink attack or similar race-based maneuver to intercept or read files they do not have permission to access. The attack requires local access and specific timing (High Access Complexity), resulting in a partial impact on confidentiality, integrity, and availability. This is a legacy vulnerability originally identified in 1995.

Affected products

  • Linux mailx

Timeline

  • 1995-12-01: disclosed: Initial publication date in NVD

References

Related threats