CVE-1999-0138
published 1996-06-26CVE-1999-0138: The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
PriorityP422high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.70%
49.1th percentile
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | a_ux | — | — |
| digital | osf_1 | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| nec | ews-ux_v | — | — |
| nec | ews-ux_v | — | — |
| nec | up-ux_v | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel 1.2.0 suidperl privileges management (XFDB-429 / SBV-23429)
vuldb·2026-04-16·CVSS 7.2
CVE-1999-0138 [HIGH] Linux Kernel 1.2.0 suidperl privileges management (XFDB-429 / SBV-23429)
A vulnerability was found in Linux Kernel 1.2.0 and classified as problematic. Affected is an unknown function of the component suidperl. Executing a manipulation can lead to improper privilege management.
This vulnerability appears as CVE-1999-0138. The attack requires local access. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
GHSA-785w-f5m3-3g56: The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access
ghsa_unreviewed·2022-04-30
CVE-1999-0138 [HIGH] GHSA-785w-f5m3-3g56: The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
1996-06-26
Published