Junglewise Threat Intelligence

CVE-1999-1392: NeXT NeXTSTEP privilege escalation in restore0.9 installation script

CVE-1999-1392 · Severity: high · CVSS 7.2 · Published 1990-10-03

Technologies: Nextstep, Next. Vendors: Next.

Executive brief

A vulnerability in the installation script for the restore utility on NeXT systems allows a local user to gain full administrative control. This could allow an unauthorized person with access to the system to view, modify, or delete any data and disrupt operations. The issue stems from a flaw in how the installation script handles permissions during setup.

Technical details

The vulnerability exists within the restore0.9 installation script provided with NeXT 1.0 and 1.0a operating systems. A local attacker can exploit this flaw to escalate their privileges to root. The root cause is a vulnerability in the script's execution logic or permission handling during the installation process. Successful exploitation grants the attacker full system access. Patches were historically made available by the vendor to address this issue.

Affected products

  • NeXT NeXTSTEP 1.0, 1.0a

Timeline

  • 1990-10-03: advisory: Initial NVD publication date
  • 1990-10-03: disclosed: Date of CERT advisory CA-1990-06

References

Related threats