2.1
CVSSv2

CVE-1999-1409

Published: 03/07/1998 Updated: 18/10/2016
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The at program in IRIX 6.2 and NetBSD 1.3.2 and previous versions allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.

Vulnerable Product Search on Vulmon Subscribe to Product

sgi irix 6.2

sgi irix 6.4

sgi irix 6.5

sgi irix 6.5.1

netbsd netbsd 1.2.1

netbsd netbsd 1.3

netbsd netbsd 1.1

netbsd netbsd 1.2

netbsd netbsd 1.3.1

netbsd netbsd

netbsd netbsd 1.0

Exploits

source: wwwsecurityfocuscom/bid/331/info A vulnerability exists in NetBSD version 132 and lower, and Silicon Graphics Inc's IRIX versions 62, 63, 64, 65 and 651 The at(1) program can be supplied with a -f flag, and an error is access validation can result in the mailing of portions of unreadable files to any user who can run at ...