Junglewise Threat Intelligence

CVE-1999-0245: Linux NIS+ authentication bypass via '+' user login

CVE-1999-0245 · Severity: medium · CVSS 4.6 · Published 1995-09-07

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A configuration flaw in the Network Information Service Plus (NIS+) on Linux systems allowed unauthorized access. Attackers could bypass standard authentication to log in as a special account designated by the '+' character. This could lead to unauthorized access to system resources and potential data compromise on affected legacy systems.

Technical details

This vulnerability stems from a configuration error in the Linux implementation of NIS+ (Network Information Service Plus). Due to improper handling of the '+' wildcard character in system authentication files or NIS+ maps, the system incorrectly validated login attempts for a user named '+'. An attacker with local access could exploit this to gain unauthorized entry into the system. This issue is primarily found in legacy Linux environments where NIS+ was utilized for distributed naming services. The impact includes a loss of confidentiality, integrity, and availability as the attacker gains a foothold on the local system.

Affected products

  • Linux NIS+ Legacy Linux distributions using NIS+

Timeline

  • 1995-09-07: disclosed: Initial publication date in NVD

References

Related threats