CVE-1999-1165
CVSS 2.0 Score 7.2 of 10 (high)
Details
Published Jul 21, 1999
Updated: Nov 20, 2024
Summary
CVE-1999-1165 is a vulnerability affecting GNU fingerd version 1.37. The issue arises from the software's failure to drop privileges prior to accessing user information. This flaw can be exploited by local users, allowing them to potentially gain root privileges by crafting malicious content in the .fingerrc file. Additionally, users may be able to read arbitrary files by creating symbolic links in .plan, .forward, or .project files.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- GNU