PT-1999-1594 · Gnu · Gnu Fingerd
Publicado
1999-07-21
·
Atualizado
2016-10-18
·
CVE-1999-1165
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GNU fingerd version 1.37
Description
The issue allows local users to gain elevated privileges or read arbitrary files. This can be achieved by exploiting the lack of proper privilege dropping before accessing user information. Specifically, a malicious program in the
.fingerrc file could lead to gaining root privileges. Additionally, symbolic links from .plan, .forward, or .project files could be used to read arbitrary files.Recommendations
For GNU fingerd version 1.37, consider restricting access to the
.fingerrc file and avoiding the use of symbolic links in .plan, .forward, or .project files until a proper fix is available. As a temporary workaround, dropping privileges before accessing user information can help mitigate the risk.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gnu Fingerd