CVE-1999-1574: Buffer Overflow

Published Jul 6, 1998
·
Updated

Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."

Affected Software

1 affected component
IBM AIX=4.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove IBM AIX nslookup from your environment.

    If nslookup is not required on AIX 4.3 systems, uninstall or remove the nslookup utility to eliminate the vulnerable component that can be triggered by long input strings.

  2. Compensating control

    Restrict access to AIX 4.3 hosts and limit who can execute nslookup. Implement network controls (firewall, ACLs) to prevent untrusted users or systems from reaching management/diagnostic services on affected hosts.

  3. Operational

    Monitor affected AIX 4.3 systems for crashes (core dumps) and other signs of exploitation. Collect and preserve forensic evidence for any suspicious activity and investigate promptly.

  4. Operational

    Apply any vendor-supplied patches or updates for nslookup on IBM AIX 4.3 as soon as IBM releases them.

Event History

Jul 6, 1998
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Apr 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1574?

CVE-1999-1574 is considered a critical vulnerability due to the potential for arbitrary code execution.

2

How do I fix CVE-1999-1574?

To fix CVE-1999-1574, you should apply the latest security patches provided by IBM for AIX 4.3.0.

3

What causes CVE-1999-1574?

CVE-1999-1574 is caused by a buffer overflow in the lex routines of nslookup due to long input strings.

4

What systems are affected by CVE-1999-1574?

CVE-1999-1574 specifically affects IBM AIX version 4.3.0.

5

Can CVE-1999-1574 be exploited remotely?

Yes, CVE-1999-1574 can potentially be exploited remotely if an attacker can send crafted long input strings to nslookup.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203