CVE Vulnerabilities

CVE-1999-0138

Published: Jun 26, 1996 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.

Affected Software

NameVendorStart VersionEnd Version
A_uxApple3.1.1 (including)3.1.1 (including)
Osf_1Digital1.3 (including)1.3 (including)
FreebsdFreebsd2.0 (including)2.0 (including)
FreebsdFreebsd2.0.5 (including)2.0.5 (including)
FreebsdFreebsd2.1.0 (including)2.1.0 (including)
Hp-uxHp8 (including)8 (including)
Hp-uxHp9 (including)9 (including)
Hp-uxHp10 (including)10 (including)
AixIbm3.2.5 (including)3.2.5 (including)
AixIbm4 (including)4 (including)
Linux_kernelLinux1.2.0 (including)1.2.0 (including)
Linux_kernelLinux2.0 (including)2.0 (including)
Asl_ux_4800Nec**
Ews-ux_vNec4.2 (including)4.2 (including)
Ews-ux_vNec4.2mp (including)4.2mp (including)
Up-ux_vNec4.2mp (including)4.2mp (including)

References