PT-1997-1226 · Linux+1 · Linux+1

Publicado

1997-02-03

·

Atualizado

2016-10-18

·

CVE-1999-1299

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux systems, including Red Hat version 4.0
Description The issue allows a user with a UID of 65535, such as "nobody", to overwrite arbitrary files on the system. This occurs because the UID 65535 is interpreted as -1 by system calls like chown, causing these calls to fail and not modify the file ownership as intended.
Recommendations For Red Hat version 4.0, consider restricting the use of the "nobody" user or other users with a UID of 65535 to prevent arbitrary file overwrites until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1299

Produtos afetados

Linux
Red Hat