CVE-1999-1572
CVSS 2.0 Score 2.1 of 10 (low)
Details
Summary
CVE-1999-1572 is a vulnerability affecting the cpio utility on FreeBSD 2.1.0 and Debian GNU/Linux 3.0, among other potential operating systems. When using the -O (archive) or -F options to create files, cpio sets an umask of 0, resulting in files being created with mode 0666. This vulnerability exposes the files to local users, enabling them to read or overwrite the files unintendedly. This issue can potentially lead to unauthorized data access or modification. It is recommended that affected systems be updated to a newer version of the cpio utility to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Red Hat Enterprise Linux
- Debian
- FreeBSD
Affected Vendors
- Debian
- Red Hat
- FreeBSD Project
- MandrakeSoft