Lucene search

K
cveMitreCVE-1999-1422
HistorySep 12, 2001 - 4:00 a.m.

CVE-1999-1422

2001-09-1204:00:00
mitre
web.nvd.nist.gov
25
slackware
path
trojan horses
security
environment variable
nvd
cve-1999-1422

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

15.7%

The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.

Affected configurations

Nvd
Node
slackwareslackware_linuxMatch2.0.35
OR
slackwareslackware_linuxMatch3.4
VendorProductVersionCPE
slackwareslackware_linux2.0.35cpe:2.3:o:slackware:slackware_linux:2.0.35:*:*:*:*:*:*:*
slackwareslackware_linux3.4cpe:2.3:o:slackware:slackware_linux:3.4:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

15.7%

Related for CVE-1999-1422