PT-1996-1028 · Perl · Sperl+1
Published
1996-06-26
·
Updated
2022-08-17
·
CVE-1999-0138
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
sperl (affected versions not specified)
suidperl (affected versions not specified)
Description
The issue concerns the suidperl and sperl programs, which fail to relinquish root privileges when switching UIDs back to the original users. This allows unauthorized access to root.
Recommendations
For sperl, consider disabling the program until a fix is available to prevent unauthorized root access.
For suidperl, restrict its use to minimize the risk of exploitation until a resolution is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sperl
Suidperl