Vulnerability Name: | CVE-1999-0754 (CCN-2180) | ||||||||
Assigned: | 1999-05-11 | ||||||||
Published: | 1999-05-11 | ||||||||
Updated: | 2008-09-09 | ||||||||
Summary: | The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CALDERA Type: UNKNOWN CSSA-1999-011.0 Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-1999-011.0 inn package allows local users to obtain su privilege Source: CCN Type: BugTraq Mailing List, Tue, 11 May 1999 11:24:06 -0400 INN 2.0 and higher. Root compromise potential Source: MITRE Type: CNA CVE-1999-0754 Source: CCN Type: OSVDB ID: 955 INN inndstart INNCONF Path Subversion Privilege Escalation Source: MISC Type: Patch, Vendor Advisory http://www.redhat.com/corp/support/errata/inn99_05_22.html Source: CCN Type: Red Hat 6.0 Security Advisory Update INN Source: CCN Type: Red Hat Linux 6.0 General Errata Red Hat Linux 6.0 (Hedwig) General Errata Source: BID Type: UNKNOWN 255 Source: CCN Type: BID-255 ISC INN inndstart INNCONF Vulnerability Source: CCN Type: SuSE Security Announcement #04 Security hole in INN Source: XF Type: UNKNOWN inn-innconf-env(2180) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |