CVE-1999-1496: Low severity Todd Miller Sudo vulnerability

Published Jun 8, 1999
·
Updated

Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.

Affected Software

3 affected components
Todd Miller Sudo=1.5
Debian Debian Linux=2.1
redhat Linux=6.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove sudo 1.5 from your environment.

    If sudo functionality is not required on the affected hosts (Debian Linux 2.1 and Red Hat 6.0), uninstall the sudo package to eliminate the information-disclosure vector.

  2. Configuration

    Edit /etc/sudoers and any included sudoers.d files to remove non-administrative users, avoid NOPASSWD and unrestricted (ALL) command allowances, and restrict which commands users may run so unprivileged local accounts cannot use sudo to probe arbitrary filenames.

    sudo 1.5 sudoers privileges = limit to trusted administrators; restrict allowed commands; remove broad NOPASSWD or ALL privileges
  3. Compensating control

    Limit or isolate untrusted local user accounts (e.g., restrict account creation, disable shell/console/SSH access for non-admin users, use host-based access controls) to reduce the risk that local users can exploit sudo to determine existence of arbitrary files.

Event History

Jun 8, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1496?

CVE-1999-1496 is classified as a moderate severity vulnerability.

2

How do I fix CVE-1999-1496?

To fix CVE-1999-1496, update to a patched version of Sudo that addresses this file enumeration issue.

3

Who is affected by CVE-1999-1496?

CVE-1999-1496 affects local users of Sudo 1.5 on Debian Linux 2.1 and Red Hat Linux 6.0.

4

What is the impact of CVE-1999-1496?

The impact of CVE-1999-1496 allows local users to identify the existence of arbitrary files on the system.

5

Is CVE-1999-1496 still a concern today?

While CVE-1999-1496 is very old, it may still be a concern for legacy systems running affected software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203