PT-1997-1226 · Linux+1 · Linux+1
Published
1997-02-03
·
Updated
2016-10-18
·
CVE-1999-1299
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux systems, including Red Hat version 4.0
Description
The issue allows a user with a UID of 65535, such as "nobody", to overwrite arbitrary files on the system. This occurs because the UID 65535 is interpreted as -1 by system calls like chown, causing these calls to fail and not modify the file ownership as intended.
Recommendations
For Red Hat version 4.0, consider restricting the use of the "nobody" user or other users with a UID of 65535 to prevent arbitrary file overwrites until a proper fix is applied.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux
Red Hat