Junglewise Threat Intelligence

CVE-1999-1218: Commodore Amiga UNIX arbitrary file read in finger

CVE-1999-1218 · Severity: low · CVSS 2.1 · Published 1993-02-18

Executive brief

A vulnerability in the finger utility of Commodore Amiga UNIX allows users who already have access to the system to read files they should not be able to see. This could lead to the exposure of sensitive system information or private user data. The issue affects older versions of the Amiga UNIX operating system.

Technical details

The finger utility in Commodore Amiga UNIX (AMIX) version 2.1p2a and earlier contains a flaw that allows local authenticated users to bypass file system permissions. By exploiting this vulnerability, an attacker can read arbitrary files on the local system, potentially including sensitive configuration or password files. The vulnerability is categorized as an information disclosure issue. While specific technical root causes like symlink following or improper argument handling are not detailed in the legacy advisory, the impact is confirmed as partial confidentiality loss. Patches were historically addressed in CERT advisory CA-1993-04.

Affected products

  • Commodore Amiga UNIX (AMIX) 2.1p2a and earlier

Timeline

  • 1993-02-18: advisory: NVD published date
  • 1993-02-18: disclosed: Original CERT advisory date

References