CVE-1999-1013: High severity IBM AIX vulnerability
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
AIX/named-xferfrom your environment.Uninstall or disable the named-xfer binary/service on affected AIX systems if it is not required. Stop the daemon and remove the executable to prevent exploitation.
- Configuration
Review and remove any nonessential or untrusted accounts from the 'system' group so that only trusted administrative accounts remain.
AIX 'system' group membership group_members = remove nonessential users - Compensating control
Apply host-based access controls (file permissions/ACLs) to restrict which users can execute or modify the named-xfer binary; restrict access to systems running named-xfer to trusted administrators only.
- Operational
Audit system files for unauthorized modifications and restore affected files from known-good backups. If exploitation is suspected, assume possible root compromise and rotate root/privileged credentials and API keys.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1013?
CVE-1999-1013 is considered to have a high severity due to the potential for unauthorized root access.
How do I fix CVE-1999-1013?
To fix CVE-1999-1013, update to a patched version of AIX that eliminates the vulnerability.
Who is affected by CVE-1999-1013?
CVE-1999-1013 affects members of the system group on AIX versions 4.1.5 and 4.2.1.
What does CVE-1999-1013 exploit?
CVE-1999-1013 exploits the -f parameter in named-xfer along with a malformed zone file.
What are the consequences of CVE-1999-1013?
The consequences of CVE-1999-1013 include the ability to overwrite system files, potentially leading to complete system compromise.