CVE-1999-0091: Buffer Overflow
Buffer overflow in AIX writesrv command allows local users to obtain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IBM AIX writesrvfrom your environment.If the writesrv command is not required, remove or disable it to eliminate the exploitation vector.
- Compensating control
Prevent untrusted local users from executing the writesrv command (for example, restrict execution via file permissions, RBAC, or local access controls) until an official vendor fix is available.
- Operational
Audit affected AIX systems for signs of privilege escalation or root compromise. If compromise is detected, restore from known-good backups and rotate any potentially exposed credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0091?
CVE-1999-0091 is considered a critical vulnerability due to its ability to allow local users to gain root access.
How do I fix CVE-1999-0091?
To fix CVE-1999-0091, apply the patches provided by IBM for affected AIX versions.
Which versions of AIX are affected by CVE-1999-0091?
CVE-1999-0091 affects AIX versions 4.1.x and 4.2.x, including specific versions like 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, and 4.2.1.
Who can be impacted by CVE-1999-0091?
Local users with access to an affected AIX system can exploit CVE-1999-0091 to obtain elevated privileges.
What is the nature of the vulnerability in CVE-1999-0091?
CVE-1999-0091 is a buffer overflow vulnerability specifically in the writesrv command of the AIX operating system.