Junglewise Threat Intelligence

CVE-1999-0112: IBM AIX buffer overflow in dtterm program for CDE

CVE-1999-0112 · Severity: high · CVSS 7.2 · Published 1997-05-01

Technologies: IBM Aix. Vendors: IBM.

Executive brief

A security vulnerability exists in the dtterm terminal emulator program used in IBM AIX systems. This flaw could allow a local user to gain unauthorized administrative control over the system. Exploitation of this issue could lead to a complete compromise of the server, including the theft of sensitive data or disruption of operations.

Technical details

A buffer overflow vulnerability exists in the dtterm terminal emulator within the Common Desktop Environment (CDE) on IBM AIX. The flaw is located in the dtterm program, which often runs with elevated (setuid root) privileges to manage terminal operations. A local attacker can exploit this by providing specially crafted input to the program, leading to memory corruption and the execution of arbitrary code with root privileges. This is a classic stack-based buffer overflow that requires local shell access to the affected system.

Affected products

  • IBM AIX Common Desktop Environment (CDE) versions prior to May 1997

Timeline

  • 1997-05-01: disclosed: Initial publication date in NVD

References

Related threats