First published: Tue May 11 1999(Updated: )
The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC INN |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0754 has a severity rating that indicates a medium risk due to the potential for local privilege escalation.
To fix CVE-1999-0754, ensure that the INN configuration file permissions are properly set and restrict the use of the INNCONF environmental variable.
Users of ISC INN software versions that allow local configuration file manipulation are affected by CVE-1999-0754.
An attacker would exploit CVE-1999-0754 by specifying an alternate configuration file through the INNCONF environment variable to gain elevated privileges.
Yes, a patch is available in later versions of ISC INN that resolves the vulnerability associated with CVE-1999-0754.