Junglewise Threat Intelligence

CVE-1999-0113: Multiple Vendors rlogin authentication bypass via -froot parameter

CVE-1999-0113 · Severity: critical · CVSS 10 · Published 1994-05-23

Executive brief

A vulnerability in certain versions of the rlogin remote access utility allows unauthorized users to gain full administrative control over a system. By providing a specific command-line parameter, an attacker can bypass standard authentication and log in as the root user. This poses a critical risk to the confidentiality and integrity of the entire server and any data stored on it.

Technical details

The rlogin utility in various Unix-like operating systems contains an argument injection vulnerability (CWE-88). By passing the '-froot' parameter, an attacker can force the service to authenticate the session as the root user without requiring a password. This is a network-based attack that requires no prior authentication. Successful exploitation results in a complete compromise of the target system with highest privileges. The vulnerability was widely addressed in the mid-1990s by patching the rlogin daemon to properly validate or reject such parameters.

Affected products

  • Multiple Vendors rlogin

Timeline

  • 1994-05-23: disclosed

References