First published: Mon Jul 13 1998(Updated: )
login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Slackware Linux | =3.1 | |
Slackware Linux | =3.2 | |
Slackware Linux | =3.3 | |
Slackware Linux | =3.4 | |
Slackware Linux | =3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1434 is considered a high severity vulnerability due to its potential to grant root privileges to any local user.
To fix CVE-1999-1434, ensure that the /etc/group file exists and is properly configured.
CVE-1999-1434 affects Slackware Linux versions 3.2, 3.3, 3.4, and 3.5.
CVE-1999-1434 is a privilege escalation vulnerability.
CVE-1999-1434 is not a remote exploit, as it requires local access to the server.