CVE-1999-1193: Critical severity NeXT NeXT vulnerability
The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove the 'me' user from the wheel group (so it is not a member of wheel) to prevent that account from using su to become root.
NeXT NeXTstep user account 'me' wheel group membership = remove
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1193?
CVE-1999-1193 is considered a critical vulnerability due to the unauthorized ability for the 'me' user to gain root access.
How do I fix CVE-1999-1193?
To fix CVE-1999-1193, limit the privileges of the 'me' user by modifying the group memberships and ensure the wheel group does not include unauthorized users.
Which versions of NeXT are affected by CVE-1999-1193?
CVE-1999-1193 affects NeXT NeXTstep version 2.1 and earlier.
What does CVE-1999-1193 enable an attacker to do?
CVE-1999-1193 allows an attacker with 'me' user access to execute the su command and obtain root privileges.
Is CVE-1999-1193 a known vulnerability?
Yes, CVE-1999-1193 is a well-documented vulnerability that has been recognized in NeXT NeXTstep systems.