| Vulnerability Name: | CVE-1999-0856 |
| Assigned: | 1999-12-01 |
| Published: | 1999-12-01 |
| Updated: | 2022-08-17 |
| Summary: | login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.
|
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)| Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | | Scope: | Scope (S): Unchanged
| | Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)| Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)| Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
| Vulnerability Type: | CWE-Other
|
| References: | Source: MITRE Type: CNA CVE-1999-0856
Source: MISC Type: UNKNOWN https://marc.info/?l=bugtraq&m=94416739411280&w=2
|
| Vulnerable Configuration: | Configuration 1: cpe:/o:slackware:slackware_linux:7.0:*:*:*:*:*:*:*
Denotes that component is vulnerable |
| BACK |