CVE-1999-0072: Buffer Overflow
Buffer overflow in AIX xdat gives root access to local users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IBM AIX xdatfrom your environment.Uninstall or remove the xdat package/executable from systems where it is not required.
- Configuration
Stop and disable the xdat service on affected AIX systems until a vendor fix is available.
IBM AIX xdat service_enabled = false - Compensating control
Limit local user access to affected hosts (restrict logins to trusted administrators), and use host-based access controls to prevent unprivileged users from executing or accessing xdat until a patch is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0072?
CVE-1999-0072 has a high severity rating due to its ability to grant root access to local users.
How do I fix CVE-1999-0072?
To fix CVE-1999-0072, update your IBM AIX system to a version that patches this vulnerability.
Which versions of AIX are affected by CVE-1999-0072?
CVE-1999-0072 affects AIX versions 4.1.1 to 4.2.1.
Who is at risk from CVE-1999-0072?
Local users on systems running vulnerable versions of AIX are at risk from CVE-1999-0072.
What type of vulnerability is CVE-1999-0072?
CVE-1999-0072 is a buffer overflow vulnerability.