The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.
References
Link | Resource |
---|---|
http://www.shmoo.com/mail/bugtraq/jul98/msg00064.html | Patch Vendor Advisory |
http://www.securityfocus.com/bid/331 | Exploit Patch Vendor Advisory |
ftp://ftp.NetBSD.ORG/pub/NetBSD/security/advisories/NetBSD-SA1998-004.txt.asc | |
http://www.iss.net/security_center/static/7577.php | |
http://marc.info/?l=bugtraq&m=90233906612929&w=2 |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 1998-07-02 21:00
Updated : 2016-10-17 19:04
NVD link : CVE-1999-1409
Mitre link : CVE-1999-1409
JSON object : View
CWE
Products Affected
sgi
- irix
netbsd
- netbsd