Junglewise Threat Intelligence

CVE-1999-0115: IBM AIX privilege escalation in bugfiler program

CVE-1999-0115 · Severity: high · CVSS 7.2 · Published 1997-09-01

Technologies: IBM Aix. Vendors: IBM.

Executive brief

A vulnerability in the AIX bugfiler utility allows a local user to gain full administrative control over the operating system. The bugfiler program is a tool used for managing software bug reports, and its exploitation could lead to a complete compromise of the system's data and availability. This issue represents a significant risk as it allows any user with basic access to the machine to escalate their privileges to the highest level.

Technical details

The AIX bugfiler utility contains a privilege escalation vulnerability that allows a local, unprivileged user to execute commands or manipulate files with root authority. While the specific vulnerability class (e.g., buffer overflow or insecure file handling) is not detailed in the brief NVD record, the impact is a full compromise of confidentiality, integrity, and availability (CVSS 2.0 score 7.2). An attacker must have local shell access to the system to exploit this flaw. Successful exploitation results in the attacker obtaining a root shell.

Affected products

  • IBM AIX

Timeline

  • 1997-09-01: disclosed

References

Related threats