First published: Mon Dec 07 1998(Updated: )
fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Linux | =2.1 | |
Linux Kernel | =2.6.20.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1276 is considered a critical vulnerability since it allows local users to gain root access.
To fix CVE-1999-1276, update the fte package to a version that drop root privileges, such as 0.46b-4.1 or later.
CVE-1999-1276 affects the fte package on Debian GNU/Linux 2.1 and Linux Kernel version 2.6.20.1.
No, CVE-1999-1276 requires local access to exploit, making it a local privilege escalation vulnerability.
The impact of CVE-1999-1276 is that local users can obtain elevated permissions, potentially compromising the entire system.