First published: Tue Jan 02 1996(Updated: )
rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rxvt | ||
Red Hat Linux | =2.1 | |
Slackware Linux | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1186 is considered a critical vulnerability as it allows local users to gain root privileges on affected systems.
To fix CVE-1999-1186, upgrade the rxvt application to a version that does not include the PRINT_PIPE option or disable this option during compilation.
CVE-1999-1186 affects various Linux operating systems, including Slackware 3.0 and RedHat 2.1.
CVE-1999-1186 can be exploited by local users who have access to run the rxvt terminal with crafted command line parameters.
A temporary workaround for CVE-1999-1186 is to restrict user access to the rxvt application until the vulnerability is patched.