PT-1999-1594 · Gnu · Gnu Fingerd

Published

1999-07-21

·

Updated

2016-10-18

·

CVE-1999-1165

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNU fingerd version 1.37
Description The issue allows local users to gain elevated privileges or read arbitrary files. This can be achieved by exploiting the lack of proper privilege dropping before accessing user information. Specifically, a malicious program in the .fingerrc file could lead to gaining root privileges. Additionally, symbolic links from .plan, .forward, or .project files could be used to read arbitrary files.
Recommendations For GNU fingerd version 1.37, consider restricting access to the .fingerrc file and avoiding the use of symbolic links in .plan, .forward, or .project files until a proper fix is available. As a temporary workaround, dropping privileges before accessing user information can help mitigate the risk.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1165

Affected Products

Gnu Fingerd