CVE-1999-0298

Slackware Linux and SunOS - Arbitrary File Write via ypbind Dot-Dot Attack

Title source: llm
STIX 2.1

Description

ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_nai
http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp

Scores

EPSS 0.0158
EPSS Percentile 81.8%

Details

Status published
Products (5)
slackware/slackware_linux 2.1
slackware/slackware_linux 2.2
slackware/slackware_linux 2.3
sun/sunos 4.1.3
sun/sunos 4.1.4
Published Feb 05, 1997
Tracked Since Feb 18, 2026