First published: Mon Sep 13 1999(Updated: )
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
cde cde | =1.0.1 | |
cde cde | =1.0.2 | |
cde cde | =1.1 | |
cde cde | =1.2 | |
cde cde | =2.0 | |
cde cde | =2.1 | |
UNIX | =4.0d | |
UNIX | =4.0e | |
UNIX | =4.0f | |
IBM AIX | =4.1 | |
IBM AIX | =4.1.1 | |
IBM AIX | =4.1.2 | |
IBM AIX | =4.1.3 | |
IBM AIX | =4.1.4 | |
IBM AIX | =4.1.5 | |
IBM AIX | =4.2 | |
IBM AIX | =4.2.1 | |
IBM AIX | =4.3 | |
IBM AIX | =4.3.1 | |
IBM AIX | =4.3.2 | |
Oracle Solaris SPARC | =2.4 | |
Oracle Solaris SPARC | =2.5.1 | |
Oracle Solaris SPARC | =2.6 | |
Oracle Solaris SPARC | =7.0 | |
Sun SunOS | =5.4 | |
Sun SunOS | =5.5 | |
Sun SunOS | =5.5.1 | |
Sun SunOS | =5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0691 is considered a high severity vulnerability due to its potential to allow local users to gain root privileges.
To fix CVE-1999-0691, update the affected CDE versions to the latest patch provided by the vendor.
CVE-1999-0691 affects multiple versions of CDE including 1.0.1, 1.0.2, 1.1, 1.2, 2.0, 2.1, and several UNIX and AIX versions.
No, CVE-1999-0691 can only be exploited by local users on the affected systems.
Exploiting CVE-1999-0691 can grant unauthorized users root privileges, potentially compromising the entire system.