CVE-1999-0093: High severity IBM AIX vulnerability
AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IBM AIX nslookupfrom your environment.Remove or disable the nslookup command on affected AIX systems until an official vendor patch or update is available.
- Compensating control
Limit local untrusted user access to affected hosts (restrict shell/logon access to trusted administrators, or isolate vulnerable systems on the network) until the vulnerability is remediated by the vendor.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0093?
CVE-1999-0093 is considered a high severity vulnerability due to the potential for local users to gain root access.
How do I fix CVE-1999-0093?
To fix CVE-1999-0093, update your IBM AIX system to a version where the nslookup command properly drops privileges.
Which versions of IBM AIX are affected by CVE-1999-0093?
CVE-1999-0093 affects IBM AIX versions 4.1, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, and 4.2.
What type of vulnerability is CVE-1999-0093?
CVE-1999-0093 is a local privilege escalation vulnerability found in the nslookup command.
Can CVE-1999-0093 be exploited remotely?
CVE-1999-0093 cannot be exploited remotely; it requires local access to the system.