First published: Tue May 14 1991(Updated: )
The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Next Nex | <=2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1193 is considered a critical vulnerability due to the unauthorized ability for the 'me' user to gain root access.
To fix CVE-1999-1193, limit the privileges of the 'me' user by modifying the group memberships and ensure the wheel group does not include unauthorized users.
CVE-1999-1193 affects NeXT NeXTstep version 2.1 and earlier.
CVE-1999-1193 allows an attacker with 'me' user access to execute the su command and obtain root privileges.
Yes, CVE-1999-1193 is a well-documented vulnerability that has been recognized in NeXT NeXTstep systems.