CVE-1999-1382

NetWare NFS - Privilege Escalation via Read Only Flag Manipulation

Title source: llm
STIX 2.1

Description

NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to "Read Only," which NetWare-NFS changes to a setuid root program.

References (4)

Core 4
Core References
Patch, Vendor Advisory x_refsource_confirm
http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=88427711321769&w=2
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/7246.php
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=90295697702474&w=2

Scores

EPSS 0.0023
EPSS Percentile 45.4%

Details

Status published
Products (1)
novell/netware
Published Dec 31, 1999
Tracked Since Feb 18, 2026