CVE Vulnerabilities

CVE-1999-1021

Published: Dec 30, 1992 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.

Affected Software

NameVendorStart VersionEnd Version
SunosSun4.1 (including)4.1 (including)
SunosSun4.1.1 (including)4.1.1 (including)
SunosSun4.1.2 (including)4.1.2 (including)

References