CVE-1999-0958: High severity todd miller sudo vulnerability
Published Jan 12, 1998
·Updated
sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.
Affected Software
3 affected components
Todd Miller Sudo=1.5.3
Todd Miller Sudo=1.5.2
Todd Miller Sudo=1.5
Event History
Jan 12, 1998
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Apr 18, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-1999-0958?
CVE-1999-0958 is considered a high severity vulnerability due to its potential to allow local users to execute arbitrary commands.
2
How do I fix CVE-1999-0958?
To fix CVE-1999-0958, upgrade to a patched version of sudo that is not vulnerable to the dot dot attack.
3
Who is affected by CVE-1999-0958?
CVE-1999-0958 affects users of sudo version 1.5.x, specifically versions 1.5, 1.5.2, and 1.5.3.
4
What are the consequences of CVE-1999-0958?
Exploitation of CVE-1999-0958 can lead to unauthorized access and execution of commands by local users.
5
Is CVE-1999-0958 still relevant today?
While CVE-1999-0958 originates from 1999, its concept of path traversal vulnerabilities remains relevant in contemporary security discussions.