Junglewise Threat Intelligence

CVE-1999-0316: Linux splitvt buffer overflow

CVE-1999-0316 · Severity: high · CVSS 7.2 · Published 1995-12-01

Vendors: Linux.

Executive brief

A security vulnerability exists in the splitvt utility, a tool used to split a terminal screen into two windows. A local user with access to the system can exploit this flaw to gain full administrative (root) privileges. This could allow an unauthorized individual to take complete control of the affected Linux system, potentially leading to data theft or system disruption.

Technical details

A buffer overflow vulnerability exists in the splitvt utility, which is typically installed with setuid root permissions to manage terminal windows. The flaw is triggered when the application fails to properly validate the length of input data, leading to memory corruption. A local attacker can exploit this by providing specially crafted input to the command, allowing them to overwrite the execution flow and execute arbitrary code with elevated root privileges. This vulnerability requires local shell access but no prior administrative permissions.

Affected products

  • Linux splitvt

Timeline

  • 1995-12-01: disclosed: Initial publication date

References