Vulnerability Name: | CVE-1999-1409 (CCN-7577) | ||||||||
Assigned: | 1998-07-03 | ||||||||
Published: | 1998-07-03 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: NETBSD Type: UNKNOWN NetBSD-SA1998-004 Source: CCN Type: BugTraq Mailing List, Fri, 3 Jul 1998 22:14:14 +0200 more about 'at' Source: CCN Type: BugTraq Mailing List, Wed, 5 Aug 1998 06:24:18 -0600 irix-6.2 "at -f" vulnerability Source: MITRE Type: CNA CVE-1999-1409 Source: CCN Type: NetBSD Security Advisory 1998-004 Problem with at(1) allows any file to be read Source: BUGTRAQ Type: UNKNOWN 19980805 irix-6.2 "at -f" vulnerability Source: CCN Type: SGI Support Web site Supportfolio Online Source: XF Type: UNKNOWN at-f-read-files(7577) Source: CCN Type: OSVDB ID: 978 Multiple Vendor at -f Arbitrary File Read Source: BID Type: Exploit, Patch, Vendor Advisory 331 Source: CCN Type: BID-331 Multiple Vendor at(1) Vulnerability Source: BUGTRAQ Type: Patch, Vendor Advisory 19980703 more about 'at' Source: XF Type: UNKNOWN at-f-read-files(7577) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |