PT-1991-1006 · Next · Nextstep
Published
1991-05-14
·
Updated
2017-10-10
·
CVE-1999-1193
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NeXTstep versions 2.1 and earlier
Description
The issue concerns the "me" user having wheel group privileges, potentially allowing the "me" user to use the su command to gain root access.
Recommendations
For NeXTstep versions 2.1 and earlier, remove the "me" user from the wheel group to prevent potential privilege escalation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextstep