CVE-1999-1313: Medium severity FreeBSD FreeBSD vulnerability
Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
freebsd/manfrom your environment.Uninstall or remove the manual page reader ('man') from systems where it is not required to prevent local users from exploiting this vulnerability to gain privileges.
- Compensating control
Restrict and harden local access: limit which accounts are allowed to log in locally (disable or remove unneeded local accounts), restrict interactive shell access to trusted administrators, and apply least-privilege policies to mitigate exploitation by local users.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1313?
CVE-1999-1313 is considered to have a high severity due to local users potentially gaining elevated privileges.
How do I fix CVE-1999-1313?
To fix CVE-1999-1313, upgrade to FreeBSD versions released after 2.2 that address this vulnerability.
What versions of FreeBSD are affected by CVE-1999-1313?
CVE-1999-1313 affects FreeBSD versions 2.2 and earlier.
Can remote users exploit CVE-1999-1313?
CVE-1999-1313 is a local vulnerability that cannot be exploited by remote users.
What is the nature of the vulnerability in CVE-1999-1313?
CVE-1999-1313 allows local users to execute a sequence of commands that can lead to privilege escalation.