First published: Fri Oct 13 1995(Updated: )
Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SGI IRIX | =5.0 | |
SGI IRIX | =5.0.1 | |
SGI IRIX | =5.1 | |
SGI IRIX | =5.1.1 | |
SGI IRIX | =5.2 | |
SGI IRIX | =5.3 | |
SGI IRIX | =5.3 | |
SGI IRIX | =6.0 | |
SGI IRIX | =6.0.1 | |
SGI IRIX | =6.0.1 | |
SGI IRIX | =6.1 | |
SGI IRIX | =6.2 | |
SGI IRIX | =6.3 | |
Digital OSF/1 | =1.2 | |
Digital OSF/1 | =1.3 | |
Digital OSF/1 | =2.0 | |
Digital OSF/1 | =3.0 | |
Digital OSF/1 | =3.2 | |
UNIX | =3.2g | |
UNIX | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0073 is considered to have a high severity due to the potential for remote root access exploitation.
To fix CVE-1999-0073, upgrade to a patched version of SGI IRIX or Digital OSF/1 that does not allow environment variable manipulation.
CVE-1999-0073 affects various versions of SGI IRIX and Digital OSF/1 systems.
Exploiting CVE-1999-0073 allows an attacker to change environment variables, which can lead to arbitrary code execution with root privileges.
A potential workaround for CVE-1999-0073 is to disable Telnet service and use more secure alternatives for remote access.