7.2
CVSSv2

CVE-1999-0708

Published: 21/09/1999 Updated: 09/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.

Vulnerable Product Search on Vulmon Subscribe to Product

infodrom cfingerd 1.4.2

Exploits

source: wwwsecurityfocuscom/bid/651/info Under systems that allow the user to change his GECOS field from the password file and do not limit its length cfingerd is vulnerable to a local root (or nobody) buffer overflow By setting a carefully designed GECOS field it is possible to execute arbitrary code with root (or nobody ) privileges ...