Vulnerability Description
The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | All versions |
Related Weaknesses (CWE)
References
- http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638
- https://exchange.xforce.ibmcloud.com/vulnerabilities/348
- http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638
- https://exchange.xforce.ibmcloud.com/vulnerabilities/348
FAQ
What is CVE-1999-0656?
CVE-1999-0656 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.
How severe is CVE-1999-0656?
CVE-1999-0656 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-0656?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.