CVE-1999-1208: Buffer Overflow
Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IBM AIX pingfrom your environment.Remove or disable the vulnerable 'ping' binary on affected AIX systems (AIX 4.2 and earlier) until an official vendor patch is available.
- Compensating control
Prevent untrusted local users from executing the 'ping' program until a vendor fix is available — e.g., restrict execution to administrators by moving the binary to a restricted location or adjusting filesystem permissions to deny execute to unprivileged accounts.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1208?
CVE-1999-1208 is considered to have a critical severity due to its potential to allow local users to gain root privileges.
How do I fix CVE-1999-1208?
To fix CVE-1999-1208, ensure that your system is updated to a version of AIX later than 4.2 that no longer contains this vulnerability.
Who is affected by CVE-1999-1208?
CVE-1999-1208 affects local users on AIX versions 3.2.5, 4.1, and 4.2.
What type of vulnerability is CVE-1999-1208?
CVE-1999-1208 is a buffer overflow vulnerability.
Can CVE-1999-1208 be exploited remotely?
CVE-1999-1208 cannot be exploited remotely as it requires local access to the system.