CVE-1999-1165: High severity GNU fingerd vulnerability

Published Jul 21, 1999
·
Updated

GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.

Affected Software

1 affected component
GNU fingerd=1.37

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove cfingerd from your environment.

    Uninstall cfingerd (GNU fingerd) from affected systems if the service is not required to eliminate the vulnerability exposure.

  2. Configuration

    Remove the setuid bit or configure fingerd to run as an unprivileged user so it does not run with elevated/root privileges.

    cfingerd (GNU fingerd) privilege level / setuid = run without root/setuid privileges
  3. Compensating control

    Prevent local users from placing or executing malicious content in ~/.fingerrc and from creating symbolic links from ~/.plan, ~/.forward, or ~/.project to sensitive files (e.g., via filesystem permissions, ACLs, or mandatory access controls).

  4. Operational

    Audit systems for signs of exploitation (malicious ~/.fingerrc, unexpected symlinks from ~/.plan/.forward/.project, or other indicators) and remediate any compromises; if compromise is suspected, contain the host and rotate credentials as appropriate.

Event History

Jul 21, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1165?

CVE-1999-1165 is considered a critical vulnerability due to its potential to allow local users to gain root privileges.

2

How do I fix CVE-1999-1165?

To fix CVE-1999-1165, upgrade GNU fingerd to a version where this vulnerability is patched.

3

Who is affected by CVE-1999-1165?

CVE-1999-1165 affects users running GNU fingerd version 1.37 on their systems.

4

What types of attacks can be performed using CVE-1999-1165?

CVE-1999-1165 can allow local users to execute malicious programs or read arbitrary files via symbolic links.

5

Is CVE-1999-1165 an issue for all versions of GNU fingerd?

No, CVE-1999-1165 specifically affects version 1.37 of GNU fingerd; later versions may not be vulnerable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203