CVE-1999-1458: Buffer Overflow
Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Digital UNIX at programfrom your environment.If the 'at' program is not required on affected systems (Digital UNIX 4.0), uninstall or remove the 'at' binary to eliminate the vulnerable component.
- Configuration
Restrict execution of the 'at' binary to root only or remove execute permission for non-root accounts (e.g., adjust file permissions) to prevent local users from invoking the vulnerable program.
at program (Digital UNIX 4.0) executable for non-root users = disabled - Compensating control
Restrict and monitor local account access: limit which users can log in or execute jobs on Digital UNIX 4.0 systems, enforce strict local account controls, and isolate vulnerable hosts from untrusted users until a vendor patch or official fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1458?
CVE-1999-1458 is considered a critical vulnerability allowing local users to gain root privileges.
How do I fix CVE-1999-1458?
To fix CVE-1999-1458, it is recommended to upgrade to a patched version of Digital UNIX.
Which versions are affected by CVE-1999-1458?
CVE-1999-1458 affects Digital UNIX versions 4.0, 4.0a, 4.0b, 4.0c, 4.0d, and 4.0e.
Who can exploit CVE-1999-1458?
CVE-1999-1458 can be exploited by local users with access to the system.
What is the impact of CVE-1999-1458?
The impact of CVE-1999-1458 includes unauthorized root access, allowing attackers to execute arbitrary commands.