Junglewise Threat Intelligence

CVE-1999-0091: IBM AIX buffer overflow in writesrv command

CVE-1999-0091 · Severity: high · CVSS 7.2 · Published 1997-10-28

Technologies: IBM Aix. Vendors: IBM.

Executive brief

A security vulnerability in the IBM AIX operating system could allow a local user to gain full administrative control of the server. The issue exists in a system command used for handling incoming messages, which can be manipulated to run unauthorized code. This could lead to a complete compromise of the system's data and operations by an individual who already has basic access to the machine.

Technical details

A buffer overflow vulnerability exists within the 'writesrv' command in IBM AIX. The 'writesrv' daemon is responsible for handling messages sent via the 'write' and 'tell' commands. By providing specially crafted input to this component, a local attacker can trigger a memory corruption event. Because the command typically runs with elevated privileges, a successful exploit allows the attacker to execute arbitrary code with root authority. This is a classic local privilege escalation (LPE) vulnerability requiring local shell access but no special user permissions.

Affected products

  • IBM AIX

Timeline

  • 1997-10-28: disclosed: Initial publication date in NVD

References

Related threats