Search Results (Refine Search)
- CPE Product Version: cpe:/a:gnu:fingerd:1.37
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-1999-1165 |
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files. Published: July 21, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 7.2 HIGH |