CVE-1999-0691: Buffer Overflow
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
CDE dtactionfrom your environment.Uninstall or disable the CDE dtaction utility if it is not required to eliminate the vulnerable component.
- Compensating control
Restrict or isolate local user access on systems that have the CDE dtaction utility installed (limit accounts with local login or shell access to trusted administrators) to reduce the risk from a vulnerability exploitable by local users.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0691?
CVE-1999-0691 is considered a high severity vulnerability due to its potential to allow local users to gain root privileges.
How do I fix CVE-1999-0691?
To fix CVE-1999-0691, update the affected CDE versions to the latest patch provided by the vendor.
What software versions are affected by CVE-1999-0691?
CVE-1999-0691 affects multiple versions of CDE including 1.0.1, 1.0.2, 1.1, 1.2, 2.0, 2.1, and several UNIX and AIX versions.
Can a remote attacker exploit CVE-1999-0691?
No, CVE-1999-0691 can only be exploited by local users on the affected systems.
What is the impact of exploiting CVE-1999-0691?
Exploiting CVE-1999-0691 can grant unauthorized users root privileges, potentially compromising the entire system.