Junglewise Threat Intelligence

CVE-1999-0014: Open Group CDE privilege escalation in dtappgather

CVE-1999-0014 · Severity: high · CVSS 7.2 · Published 1998-01-21

Executive brief

A security vulnerability exists in the Common Desktop Environment (CDE), a graphical user interface used on many older Unix-based operating systems. A specific utility within this environment, dtappgather, contains a flaw that allows a local user to gain unauthorized administrative privileges or crash the system. This could lead to a total loss of system confidentiality and control by an unauthorized individual.

Technical details

A vulnerability exists in the dtappgather utility within the Common Desktop Environment (CDE). The flaw allows a local attacker to perform an escalation of privilege or cause a denial of service. The root cause is typically associated with insecure file handling or environment variable processing by the setuid-root dtappgather binary. An attacker with local access can exploit this to gain root-level permissions or disrupt system availability. Patches were historically released by vendors such as Sun Microsystems and HP to address this issue.

Affected products

  • Open Group Common Desktop Environment (CDE)

Timeline

  • 1998-01-21: disclosed: Initial publication date

References

Related threats