CVE-1999-0118: High severity IBM AIX vulnerability
AIX infod allows local users to gain root access through an X display.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
infod (AIX)from your environment.Uninstall or remove the infod component if it is not required on the system.
- Configuration
Stop and disable the infod service on affected AIX systems to prevent local users from accessing it via an X display.
AIX infod service_enabled = false - Compensating control
Restrict access to the X server/display to trusted administrative accounts only (for example, remove untrusted users' X access, enforce X authentication/authorization, and apply host-based access controls) to mitigate exploitation until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0118?
CVE-1999-0118 is considered a high-severity vulnerability that allows local users to gain root access.
How do I fix CVE-1999-0118?
To fix CVE-1999-0118, you should apply the latest security patches provided by IBM for the affected AIX versions.
Which systems are affected by CVE-1999-0118?
CVE-1999-0118 affects IBM AIX versions 3.2, 4.1, 4.2, and 4.3.
What type of attack does CVE-1999-0118 enable?
CVE-1999-0118 enables local users to exploit an X display to elevate their privileges to root access.
Is there a workaround for CVE-1999-0118?
A temporary workaround for CVE-1999-0118 includes restricting access to the X display to trusted users only.