Local Privilege Escalation Vulnerability in NeXT 1.0a and 1.0
CVE-1999-1391

Currently unrated

Key Information:

Vendor

Next

Status
Vendor
CVE Published:
3 October 1990

What is CVE-1999-1391?

The vulnerability in NeXTSTEP 1.0a and 1.0 arises due to improper security configurations in the npd program coupled with insufficient directory permissions. This allows local users to exploit publicly accessible printers to gain elevated privileges, potentially compromising the system integrity. Organizations using these versions must assess their directory settings and implement robust security measures to mitigate potential exploits.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.