Junglewise Threat Intelligence

CVE-1999-1390: Debian suidmanager privilege escalation in suidexec

CVE-1999-1390 · Severity: high · CVSS 7.2 · Published 1998-04-28

Technologies: Debian Linux. Vendors: Debian.

Executive brief

A vulnerability in the suidmanager utility on Debian 2.0 allows a local user to gain full administrative control of the system. By running a specific command with a malicious program as an argument, an attacker can bypass security restrictions and execute code with root privileges. This could lead to a complete system takeover and unauthorized access to all data on the machine.

Technical details

The suidexec utility within the suidmanager package (version 0.18) on Debian 2.0 contains a flaw in how it handles command-line arguments. A local, unprivileged attacker can invoke suidexec and provide a path to a malicious executable as an argument. Because suidexec does not properly validate or restrict the programs it executes while running with elevated privileges, it will run the attacker's program as the root user. This results in a complete privilege escalation from a standard user to root.

Affected products

  • Debian suidmanager 0.18

Timeline

  • 1998-04-28: disclosed

References

Related threats