CVE-1999-1075: Medium severity IBM AIX vulnerability

Published Mar 18, 1998
·
Updated

inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.

Affected Software

1 affected component
IBM AIX=4.1.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove IBM AIX ttdbserver (ToolTalk) from your environment.

    Uninstall or remove the ttdbserver (ToolTalk server) from affected AIX systems if the service is not required.

  2. Configuration

    Disable the ttdbserver (ToolTalk server) in inetd's configuration so inetd will not spawn the service (preventing inetd from listening on the dynamically-assigned port and the adjacent port).

    inetd / ttdbserver (ToolTalk) ttdbserver_service = disabled
  3. Compensating control

    At the network perimeter or host firewall, block or restrict incoming access to the ToolTalk/ttdbserver ports (including the adjacent port that inetd may listen on, i.e. N-1) to trusted hosts only to mitigate denial-of-service attempts.

Event History

Mar 18, 1998
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1075?

CVE-1999-1075 is classified as a denial of service vulnerability.

2

How do I fix CVE-1999-1075?

To fix CVE-1999-1075, you should apply patches provided by IBM for AIX version 4.1.5.

3

What are the consequences of CVE-1999-1075?

The consequences of CVE-1999-1075 include potential denial of service caused by a large number of connections to an unintended port.

4

Which systems are affected by CVE-1999-1075?

CVE-1999-1075 affects systems running IBM AIX version 4.1.5.

5

Can CVE-1999-1075 be exploited remotely?

Yes, CVE-1999-1075 can be exploited remotely through a large number of connections to port N-1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203