CVE-1999-0656

Linux Kernel - Unauthenticated Username Enumeration via ugidd RPC Interface

Title source: llm
STIX 2.1

Description

The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/348

Scores

EPSS 0.0155
EPSS Percentile 72.9%

Details

CWE
CWE-16
Status published
Products (1)
linux/linux_kernel
Published Jan 01, 1999
Tracked Since Feb 18, 2026