Executive brief
A vulnerability in the finger utility of Commodore Amiga UNIX allows users who already have access to the system to read files they should not be able to see. This could lead to the exposure of sensitive system information or private user data. The issue affects older versions of the Amiga UNIX operating system.
Technical details
The finger utility in Commodore Amiga UNIX (AMIX) version 2.1p2a and earlier contains a flaw that allows local authenticated users to bypass file system permissions. By exploiting this vulnerability, an attacker can read arbitrary files on the local system, potentially including sensitive configuration or password files. The vulnerability is categorized as an information disclosure issue. While specific technical root causes like symlink following or improper argument handling are not detailed in the legacy advisory, the impact is confirmed as partial confidentiality loss. Patches were historically addressed in CERT advisory CA-1993-04.
Affected products
- Commodore Amiga UNIX (AMIX) 2.1p2a and earlier
Timeline
- 1993-02-18: advisory: NVD published date
- 1993-02-18: disclosed: Original CERT advisory date