CVE
- Id
- 78
- CVE No.
- CVE-1999-0078
- Status
- Candidate
- Description
- pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
- Phase
- Modified (19990621-01)
- Votes
- ACCEPT(5) Collins, Frech, Landfield, Northcutt, Shostack | NOOP(1) Baker | RECAST(1) Christey
- Comments
- Christey> This candidate should be SPLIT, since there are two separate | software flaws. One is a symlink race and the other is a | shell metacharacter problem. | Christey> The permissions part of this vulnerability appears to | overlap with CVE-1999-0353 | Christey> SGI:20020802-01-I