CVE-1999-1385
CVSS 2.0 Score 7.2 of 10 (high)
Details
Published Dec 19, 1996
Updated: Nov 20, 2024
Summary
CVE-1999-1385 is a buffer overflow vulnerability affecting the ppp program in FreeBSD 2.1 and earlier versions. A local user can exploit this issue by setting a excessively long HOME environment variable, resulting in the program writing past the intended buffer bounds. This vulnerability grants the attacker elevated privileges, posing a significant security risk for impacted systems. It is recommended that users upgrade to the latest FreeBSD release to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FreeBSD
Affected Vendors
- FreeBSD Project