CVE-1999-1391: High severity NeXT NeXT vulnerability

Published Oct 3, 1990
·
Updated

Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.

Affected Software

2 affected components
NeXT NeXT=1.0a
NeXT NeXT=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove npd from your environment.

    Remove or disable the npd program if it is not required. If npd must remain, run it with least privilege and restrict access until a patch is available.

  2. Configuration

    Disable publicly accessible printers or restrict printer access to authorized users only (do not allow printers to be publicly accessible).

    printer service public_access = disabled
  3. Configuration

    Correct weak directory permissions for directories used by the npd program and related printer services—remove world-writable permissions and ensure ownership is limited to root or appropriate service accounts.

    NeXT filesystem directories used by npd directory_permissions = restrict write/execute to appropriate owners
  4. Compensating control

    Restrict network-level access to printer services (for example via firewall, ACLs or network segmentation) so printers are not publicly accessible and only trusted hosts can reach them.

Event History

Oct 3, 1990
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1391?

CVE-1999-1391 has a moderate severity level due to potential privilege escalation risks for local users.

2

How do I fix CVE-1999-1391?

To mitigate CVE-1999-1391, ensure proper directory permissions are set to prevent unauthorized access to the npd program.

3

Which versions are affected by CVE-1999-1391?

CVE-1999-1391 affects NeXT versions 1.0 and 1.0a.

4

Who can be impacted by CVE-1999-1391?

Local users have the potential to exploit the CVE-1999-1391 vulnerability to gain elevated privileges.

5

What vulnerabilities does CVE-1999-1391 exploit?

CVE-1999-1391 exploits weak directory permissions in combination with the functionality of the npd program.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203