CVE-1999-0298

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/02/1997
Last modified:
20/11/2024

Description

ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:slackware:slackware_linux:2.1:*:*:*:*:*:*:*
cpe:2.3:o:slackware:slackware_linux:2.2:*:*:*:*:*:*:*
cpe:2.3:o:slackware:slackware_linux:2.3:*:*:*:*:*:*:*
cpe:2.3:o:sun:sunos:4.1.3:*:*:*:*:*:*:*
cpe:2.3:o:sun:sunos:4.1.4:*:*:*:*:*:*:*