CVE-1999-0434
published 1999-03-30CVE-1999-0434: XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain…
PriorityP423high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.11%
62.3th percentile
XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| caldera | openlinux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| netbsd | netbsd | — | — |
| redhat | linux | — | — |
| suse | suse_linux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NetBSD/Linux XFree86 xfs symlink (BID-359)
vuldb·2026-04-19·CVSS 7.5
CVE-1999-0434 [HIGH] NetBSD/Linux XFree86 xfs symlink (BID-359)
A vulnerability was found in NetBSD and Linux. It has been declared as problematic. Impacted is an unknown function of the file xfs of the component XFree86. The manipulation results in symlink following.
This vulnerability is known as CVE-1999-0434. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-2g65-vp99-qwv8: XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain
ghsa_unreviewed·2022-04-30
CVE-1999-0434 [HIGH] GHSA-2g65-vp99-qwv8: XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain
XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
1999-03-30
Published