First published: Wed Oct 29 1997(Updated: )
AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =4.1.4 | |
IBM AIX | =4.2 | |
IBM AIX | =4.1.5 | |
IBM AIX | =4.1.1 | |
IBM AIX | =4.1.2 | |
IBM AIX | =4.1 | |
IBM AIX | =4.1.3 | |
=4.1 | ||
=4.1.1 | ||
=4.1.2 | ||
=4.1.3 | ||
=4.1.4 | ||
=4.1.5 | ||
=4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0093 is considered a high severity vulnerability due to the potential for local users to gain root access.
To fix CVE-1999-0093, update your IBM AIX system to a version where the nslookup command properly drops privileges.
CVE-1999-0093 affects IBM AIX versions 4.1, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, and 4.2.
CVE-1999-0093 is a local privilege escalation vulnerability found in the nslookup command.
CVE-1999-0093 cannot be exploited remotely; it requires local access to the system.