HIGH · 7.2

CVE-1999-1434

login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to a...

Vulnerability Description

login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SlackwareSlackware Linux3.1

References

FAQ

What is CVE-1999-1434?

CVE-1999-1434 is a vulnerability with a CVSS score of 7.2 (HIGH). login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to a...

How severe is CVE-1999-1434?

CVE-1999-1434 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-1999-1434?

Check the references section above for vendor advisories and patch information. Affected products include: Slackware Slackware Linux.