PT-1997-1226 · Linux+1 · Linux+1

Published

1997-02-03

·

Updated

2016-10-18

·

CVE-1999-1299

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux systems, including Red Hat version 4.0
Description The issue allows a user with a UID of 65535, such as "nobody", to overwrite arbitrary files on the system. This occurs because the UID 65535 is interpreted as -1 by system calls like chown, causing these calls to fail and not modify the file ownership as intended.
Recommendations For Red Hat version 4.0, consider restricting the use of the "nobody" user or other users with a UID of 65535 to prevent arbitrary file overwrites until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1299

Affected Products

Linux
Red Hat