{"id":"CVE-1999-1491","title":"abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.","summary":"abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.","severity":"high","cvss":7.2,"cvssVector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","published":"1996-02-02","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-1491","references":[{"url":"http://marc.info/?l=bugtraq&m=87602167418994&w=2","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/354","label":"cve@mitre.org"},{"url":"http://marc.info/?l=bugtraq&m=87602167418994&w=2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/354","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.01907,"epssPercentile":0.78572,"ingestedAt":"2026-06-22T15:59:08.059Z","exploitAvailable":true,"exploits":{"exploitdb":true,"checkedAt":"2026-09-21T15:23:31.812Z"},"slug":"CVE-1999-1491","body":"## Overview\n\nabuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":39.6,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[]}