Vulnerability Name: | CVE-1999-1288 (CCN-1406) | ||||||||
Assigned: | 1998-11-19 | ||||||||
Published: | 1998-11-19 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: Caldera International, Inc. Security Advisory SA-1998.35 Suid problem in samba Source: CCN Type: BugTraq Mailing List, 19 Nov 1998 18:20:18 Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux Source: MITRE Type: CNA CVE-1999-1288 Source: CALDERA Type: Patch, Vendor Advisory SA-1998.35 Source: CCN Type: OSVDB ID: 7529 Samba wsmbconf Command Execution and Privilege Escalation Source: BUGTRAQ Type: UNKNOWN 19981119 Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux Source: XF Type: UNKNOWN samba-wsmbconf(1406) Source: XF Type: UNKNOWN samba-wsmbconf(1406) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |