Junglewise Threat Intelligence

CVE-1999-1498: Slackware Linux pkgtool symlink attack in reply file

CVE-1999-1498 · Severity: low · CVSS 3.6 · Published 1998-04-06

Technologies: Slackware Linux. Vendors: Slackware.

Executive brief

A vulnerability in the Slackware Linux package management tool allows a local user to gain unauthorized access to system files. By manipulating temporary files used during software installation, an attacker can read or modify sensitive data they should not have access to. This could lead to a compromise of system integrity or the exposure of private information.

Technical details

The pkgtool utility in Slackware Linux 3.4 is vulnerable to a symbolic link (symlink) race condition. The application creates a temporary 'reply' file in a predictable or insecure manner, allowing a local attacker to create a symlink at that location pointing to an arbitrary file on the system. When pkgtool operates on this file with elevated privileges, it follows the symlink, enabling the attacker to read from or write to sensitive files (such as system configuration or password files) that are otherwise restricted. This is a classic insecure temporary file vulnerability.

Affected products

  • Slackware Slackware Linux 3.4

Timeline

  • 1998-04-06: disclosed: Initial publication date

References

Related threats