CVE-1999-1392: High severity NeXT NeX vulnerability
Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
NeXT restore0.9from your environment.Remove/uninstall the restore0.9 installation script from NeXT 1.0a and NeXT 1.0 installations and do not run this script on any systems.
- Configuration
Change filesystem permissions so only the root account can execute the script (ensure non-root users cannot execute or read the script).
NeXT restore0.9 installation script file_permissions = executable only by root - Compensating control
Restrict local/interactive access to affected NeXT systems to trusted administrative accounts only; prevent unprivileged local users from accessing the installation script (use host-based access controls or local account restrictions).
- Operational
Audit all NeXT 1.0a and 1.0 systems for the presence of restore0.9 and for signs of local privilege escalation. If exploitation is suspected, isolate affected systems and rotate/root account credentials or rebuild systems as appropriate.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1392?
CVE-1999-1392 is considered a critical vulnerability due to its ability to allow local users to gain root privileges.
How do I fix CVE-1999-1392?
To fix CVE-1999-1392, ensure that the installation scripts are properly secured and not accessible to local users.
Who is affected by CVE-1999-1392?
CVE-1999-1392 affects users of NeXT 1.0 and 1.0a software installations.
What can attackers do with CVE-1999-1392?
Attackers can exploit CVE-1999-1392 to gain unauthorized root access, potentially leading to full system compromise.
Is there a patch available for CVE-1999-1392?
There are no public patches for CVE-1999-1392; users are advised to implement workarounds to mitigate the risk.