CVE-1999-1382: High severity Novell NetWare FTP Server vulnerability
NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to "Read Only," which NetWare-NFS changes to a setuid root program.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable NetWare NFS mode 1 and 2 (which implement the 'Read Only' flag by changing ownership to root) to prevent local users from creating setuid programs that become setuid root.
Novell NetWare NFS (mode 1 and 2) NFS mode = disable mode 1 and 2
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1382?
CVE-1999-1382 has a high severity rating due to the potential for local users to gain root privileges.
How do I fix CVE-1999-1382?
To mitigate CVE-1999-1382, ensure proper file permissions and avoid using the "Read Only" flag without adequate security measures.
Who is affected by CVE-1999-1382?
CVE-1999-1382 affects users of Novell NetWare that utilize NFS mode 1 and 2.
What causes CVE-1999-1382?
CVE-1999-1382 is caused by the improper implementation of the "Read Only" flag in Unix by NetWare NFS.
Can CVE-1999-1382 be exploited remotely?
CVE-1999-1382 is a local privilege escalation vulnerability that requires local access to exploit.