CVE Vulnerabilities

CVE-1999-1021

Published: Dec 30, 1992 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.

Affected Software

Name Vendor Start Version End Version
Sunos Sun 4.1 (including) 4.1 (including)
Sunos Sun 4.1.1 (including) 4.1.1 (including)
Sunos Sun 4.1.2 (including) 4.1.2 (including)

References