CVE-1999-1385

CVSS 2.0 Score 7.2 of 10 (high)

Details

Published Dec 19, 1996
Updated: Nov 20, 2024

Summary

CVE-1999-1385 is a buffer overflow vulnerability affecting the ppp program in FreeBSD 2.1 and earlier versions. A local user can exploit this issue by setting a excessively long HOME environment variable, resulting in the program writing past the intended buffer bounds. This vulnerability grants the attacker elevated privileges, posing a significant security risk for impacted systems. It is recommended that users upgrade to the latest FreeBSD release to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share