Junglewise Threat Intelligence

CVE-1999-0092: IBM AIX privilege escalation in portmir command

CVE-1999-0092 · Severity: high · CVSS 7.2 · Published 1997-10-29

Technologies: IBM Aix. Vendors: IBM.

Executive brief

A security vulnerability in the IBM AIX operating system allows local users to gain full administrative control of the system. The issue exists in the 'portmir' command, which is used for monitoring terminal sessions. An attacker with basic access to the system could exploit this flaw to bypass security restrictions and take over the entire machine.

Technical details

The IBM AIX 'portmir' command contains multiple unspecified vulnerabilities that facilitate local privilege escalation. The 'portmir' utility is typically used to mirror or monitor another user's terminal session. Because this command often requires elevated privileges to interact with other terminal devices, flaws in its implementation allow a local, unprivileged attacker to execute arbitrary code or manipulate system states to gain root-level access. The attack requires local shell access but no special user permissions. While specific technical details like buffer overflows or race conditions are not detailed in the legacy advisory, the impact is a complete compromise of system confidentiality, integrity, and availability.

Affected products

  • IBM AIX

Timeline

  • 1997-10-29: disclosed: Initial publication date in NVD

References

Related threats