CVE-1999-1021
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/12/1992
Last modified:
20/11/2024
Description
NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.
Impact
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:sun:sunos:4.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:sun:sunos:4.1.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:sun:sunos:4.1.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/117&type=0&nav=sec.sba
- http://www.cert.org/advisories/CA-1992-15.html
- http://www.securityfocus.com/bid/47
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/117&type=0&nav=sec.sba
- http://www.cert.org/advisories/CA-1992-15.html
- http://www.securityfocus.com/bid/47
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82