CVE-1999-1572

low
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.

References

http://marc.info/?l=bugtraq&m=110763404701519&w=2

http://secunia.com/advisories/14357

http://secunia.com/advisories/17063

http://secunia.com/advisories/17532

http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf

http://www.debian.org/security/2005/dsa-664

http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391

http://www.mandriva.com/security/advisories?name=MDKSA-2005:032

http://www.redhat.com/support/errata/RHSA-2005-073.html

http://www.redhat.com/support/errata/RHSA-2005-080.html

http://www.redhat.com/support/errata/RHSA-2005-806.html

http://www.trustix.org/errata/2005/0003/

https://exchange.xforce.ibmcloud.com/vulnerabilities/19167

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10888

Details

Source: MITRE

Published: 1996-07-16

Updated: 2017-10-19

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
20697Ubuntu 4.10 : cpio vulnerability (USN-75-1)NessusUbuntu Local Security Checks
low
20204RHEL 2.1 : cpio (RHSA-2005:806)NessusRed Hat Local Security Checks
low
17181RHEL 4 : cpio (RHSA-2005:073)NessusRed Hat Local Security Checks
medium
17146RHEL 3 : cpio (RHSA-2005:080)NessusRed Hat Local Security Checks
low
16375Mandrake Linux Security Advisory : cpio (MDKSA-2005:032-1)NessusMandriva Local Security Checks
low
16300Debian DSA-664-1 : cpio - broken file permissionsNessusDebian Local Security Checks
low