PT-1998-1216 · Slackware · Slackware Linux

Published

1998-07-13

·

Updated

2016-10-18

·

CVE-1999-1434

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Slackware Linux versions 3.2 through 3.5
Description The issue arises from improper error checking when the /etc/group file is missing, preventing the system from dropping privileges. As a result, any local user who logs on to the server is assigned root privileges.
Recommendations For versions 3.2 through 3.5, ensure the /etc/group file exists and is properly configured to prevent privilege escalation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1434

Affected Products

Slackware Linux