Junglewise Threat Intelligence

CVE-1999-0122: IBM AIX buffer overflow in lchangelv

CVE-1999-0122 · Severity: high · CVSS 7.2 · Published 1997-07-21

Technologies: IBM Aix. Vendors: IBM.

Executive brief

A security vulnerability exists in the IBM AIX operating system within a utility used for managing logical volumes. A local user on the system can exploit this flaw to bypass security restrictions and gain full administrative (root) control over the server. This could lead to a complete compromise of the system, including unauthorized access to all data and the ability to disrupt operations.

Technical details

A buffer overflow vulnerability exists in the 'lchangelv' executable in IBM AIX. The 'lchangelv' utility is used to change the characteristics of a logical volume and typically requires elevated privileges or is installed with the setuid bit. By providing specially crafted, overly long input to the command, a local attacker can overflow a buffer on the stack or heap to overwrite memory and redirect execution flow. Successful exploitation allows an unprivileged local user to execute arbitrary code with root-level permissions. This is a classic local privilege escalation vulnerability.

Affected products

  • IBM AIX

Timeline

  • 1997-07-21: disclosed: Initial publication date in NVD.

References

Related threats