7.2
CVSSv2

CVE-1999-1434

Published: 13/07/1998 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

login in Slackware Linux 3.2 up to and including 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.

Vulnerable Product Search on Vulmon Subscribe to Product

slackware slackware linux 3.5

slackware slackware linux 3.3

slackware slackware linux 3.4

slackware slackware linux 3.1

slackware slackware linux 3.2

Exploits

source: wwwsecurityfocuscom/bid/155/info Due to the way /bin/login behaves when a /etc/group file is not present under Slackware's version of the password shadowing suite, users who log in while this file is not present will be given uid and gid 0 This will allow them unrestricted access to the machine This vulnerability is present in a ...