Search

published date: February 3, 1997

CVE-1999-1299 : rcp on various Linux...

Description

rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.

Product(s):

  • Red Hat Linux 4.0
  • Slackware Linux 3.1

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-1999-1299, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-1999-1299 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?