CVE Vulnerabilities

CVE-1999-1021

Published: Dec 30, 1992 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.

Affected Software

Name Vendor Start Version End Version
Sunos Sun 4.1 (including) 4.1 (including)
Sunos Sun 4.1.1 (including) 4.1.1 (including)
Sunos Sun 4.1.2 (including) 4.1.2 (including)

References