PT-1997-1226 · Linux+1 · Linux+1
Publicado
1997-02-03
·
Atualizado
2016-10-18
·
CVE-1999-1299
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux systems, including Red Hat version 4.0
Description
The issue allows a user with a UID of 65535, such as "nobody", to overwrite arbitrary files on the system. This occurs because the UID 65535 is interpreted as -1 by system calls like chown, causing these calls to fail and not modify the file ownership as intended.
Recommendations
For Red Hat version 4.0, consider restricting the use of the "nobody" user or other users with a UID of 65535 to prevent arbitrary file overwrites until a proper fix is applied.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux
Red Hat