Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-1999-1382

Overview

Vulnerability Score 7.2 7.2
CVE Id CVE-1999-1382
Last Modified 05 Sep 2008 04:19:23
Published 31 Dec 1999 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-1999-1382

Summary

NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to "Read Only," which NetWare-NFS changes to a setuid root program.

Vulnerable Systems

Operating System

  • Novell Netware


References

CONFIRM - http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551

BUGTRAQ - 19980812 Re: Netware NFS (fwd)

BUGTRAQ - 19980108 NetWare NFS

XF - netware-nfs-file-ownership(7246)


Last Updated: 27 May 2016 10:35:24