VulnerabilityModified
CVE-1999-1554
/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.
LOW 2.1EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Affected
- sgi/irix
- Source
- cve@mitre.org
References
- http://www.cert.org/advisories/CA-1990-08.htmlPatch, Third Party Advisory, US Government Resource
- http://www.iss.net/security_center/static/3164.php
- http://www.securityfocus.com/bid/13Patch, Vendor Advisory
- http://www.cert.org/advisories/CA-1990-08.htmlPatch, Third Party Advisory, US Government Resource
- http://www.iss.net/security_center/static/3164.php
- http://www.securityfocus.com/bid/13Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.