PT-1998-1216 · Slackware · Slackware Linux

Publicado

1998-07-13

·

Atualizado

2016-10-18

·

CVE-1999-1434

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Slackware Linux versions 3.2 through 3.5
Description The issue arises from improper error checking when the /etc/group file is missing, preventing the system from dropping privileges. As a result, any local user who logs on to the server is assigned root privileges.
Recommendations For versions 3.2 through 3.5, ensure the /etc/group file exists and is properly configured to prevent privilege escalation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1434

Produtos afetados

Slackware Linux