First published: Thu Sep 23 1999(Updated: )
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =4.2.1 | |
IBM AIX | =4.1.5 | |
=4.1.5 | ||
=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1013 is considered to have a high severity due to the potential for unauthorized root access.
To fix CVE-1999-1013, update to a patched version of AIX that eliminates the vulnerability.
CVE-1999-1013 affects members of the system group on AIX versions 4.1.5 and 4.2.1.
CVE-1999-1013 exploits the -f parameter in named-xfer along with a malformed zone file.
The consequences of CVE-1999-1013 include the ability to overwrite system files, potentially leading to complete system compromise.