Vulnerability Description
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Fingerd | 1.37 |
References
- http://marc.info/?l=bugtraq&m=93268249021561&w=2
- http://www.securityfocus.com/archive/1/2478ExploitVendor Advisory
- http://www.securityfocus.com/bid/535PatchVendor Advisory
- http://marc.info/?l=bugtraq&m=93268249021561&w=2
- http://www.securityfocus.com/archive/1/2478ExploitVendor Advisory
- http://www.securityfocus.com/bid/535PatchVendor Advisory
FAQ
What is CVE-1999-1165?
CVE-1999-1165 is a vulnerability with a CVSS score of 7.2 (HIGH). GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) re...
How severe is CVE-1999-1165?
CVE-1999-1165 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-1165?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Fingerd.