Junglewise Threat Intelligence

CVE-1999-0137: Linux dip buffer overflow in dial-up IP utility

CVE-1999-0137 · Severity: high · CVSS 7.2 · Published 1996-07-09

Vendors: Linux.

Executive brief

A vulnerability in the 'dip' utility, a tool used on older Linux systems to manage dial-up internet connections, allows a local user to take full control of the computer. By exploiting a technical flaw in how the program handles data, an attacker with basic access can bypass security restrictions to gain administrative (root) privileges. This could lead to a total compromise of the system, including the theft of sensitive data or the installation of malicious software.

Technical details

A buffer overflow vulnerability exists in the 'dip' (Dialup IP Protocol Driver) utility commonly found in legacy Linux distributions. The flaw is triggered when the program fails to properly validate the length of input data, allowing a local attacker to overwrite memory and execute arbitrary code with elevated privileges. Because 'dip' often runs with setuid root permissions to manage network interfaces, successful exploitation results in a full local privilege escalation to root. This vulnerability is exploitable by any user with local shell access to the affected system.

Affected products

  • Linux dip Legacy Linux distributions (circa 1996)

Timeline

  • 1996-07-09: disclosed: Initial publication date in NVD

References