First published: Fri Dec 31 1999(Updated: )
NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to "Read Only," which NetWare-NFS changes to a setuid root program.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell NetWare | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1382 has a high severity rating due to the potential for local users to gain root privileges.
To mitigate CVE-1999-1382, ensure proper file permissions and avoid using the "Read Only" flag without adequate security measures.
CVE-1999-1382 affects users of Novell NetWare that utilize NFS mode 1 and 2.
CVE-1999-1382 is caused by the improper implementation of the "Read Only" flag in Unix by NetWare NFS.
CVE-1999-1382 is a local privilege escalation vulnerability that requires local access to exploit.