VulnerabilityModified
CVE-1999-0380
SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.
MEDIUM 4.6EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Affected
- seattle lab software/slmail
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=91996412724720&w=2
- http://marc.info/?l=ntbugtraq&m=91999015212415&w=2
- http://marc.info/?l=ntbugtraq&m=92110501504997&w=2
- http://www.securityfocus.com/bid/497
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5392
- http://marc.info/?l=bugtraq&m=91996412724720&w=2
- http://marc.info/?l=ntbugtraq&m=91999015212415&w=2
- http://marc.info/?l=ntbugtraq&m=92110501504997&w=2
- http://www.securityfocus.com/bid/497
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5392
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.