Junglewise Threat Intelligence

CVE-1999-0097: IBM AIX and Sun Solaris command injection in FTP client

CVE-1999-0097 · Severity: critical · CVSS 10 · Published 1997-10-29

Technologies: IBM Aix. Vendors: Sun Microsystems, IBM.

Executive brief

The FTP client in IBM AIX and Sun Solaris operating systems contains a vulnerability that allows a malicious server to take control of a user's computer. When a user connects to a compromised or malicious FTP server, the server can send specially crafted commands that force the user's system to execute arbitrary programs. This could lead to a full system takeover, data theft, or the installation of malware.

Technical details

A command injection vulnerability exists in the FTP client of AIX and Solaris. The issue stems from improper sanitization of filenames or server responses containing shell metacharacters, such as the pipe (|) character. An attacker hosting a malicious FTP server can exploit this by returning crafted strings that the client passes to a shell for execution. This allows for remote code execution (RCE) on the client machine with the privileges of the user running the FTP session. The attack is delivered over the network and requires the victim to connect to the attacker-controlled server.

Affected products

  • IBM AIX
  • Sun Microsystems Solaris

Timeline

  • 1997-10-29: disclosed

References

Related threats