{"id":"CVE-1999-1572","title":"cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrit…","summary":"cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrit…","severity":"low","cvss":2.1,"cvssVector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","published":"1996-07-16","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-1572","references":[{"url":"http://marc.info/?l=bugtraq&m=110763404701519&w=2","label":"cve@mitre.org"},{"url":"http://secunia.com/advisories/14357","label":"cve@mitre.org"},{"url":"http://secunia.com/advisories/17063","label":"cve@mitre.org"},{"url":"http://secunia.com/advisories/17532","label":"cve@mitre.org"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf","label":"cve@mitre.org"},{"url":"http://www.debian.org/security/2005/dsa-664","label":"cve@mitre.org"},{"url":"http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391","label":"cve@mitre.org"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:032","label":"cve@mitre.org"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-073.html","label":"cve@mitre.org"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-080.html","label":"cve@mitre.org"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-806.html","label":"cve@mitre.org"},{"url":"http://www.trustix.org/errata/2005/0003/","label":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19167","label":"cve@mitre.org"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10888","label":"cve@mitre.org"},{"url":"http://marc.info/?l=bugtraq&m=110763404701519&w=2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/14357","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/17063","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/17532","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.debian.org/security/2005/dsa-664","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:032","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-073.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-080.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-806.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.trustix.org/errata/2005/0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19167","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10888","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00551,"epssPercentile":0.44708,"ingestedAt":"2026-06-22T15:59:08.084Z","slug":"CVE-1999-1572","body":"## Overview\n\ncpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":12,"depthScoreParts":{"impact":11.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}