CVE-1999-1296
CVSS 2.0 Score 7.2 of 10 (high)
Details
Published Apr 29, 1997
Updated: Nov 20, 2024
Summary
CVE-1999-1296 is a vulnerability affecting Kerberos V authentication system. This issue involves a buffer overflow in the Kerberos IV compatibility libraries. Maliciously crafted lines in a kerberos configuration file, which can be set via the KRB_CONF environmental variable, can lead to local users gaining root privileges. This flaw poses a serious risk, as it allows unauthorized users to elevate their privileges and potentially gain control over the system. It is essential that affected systems are updated to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Massachusetts Institute of Technology