Junglewise Threat Intelligence

CVE-1999-1034: AT&T System V Release 4 privilege escalation in login

CVE-1999-1034 · Severity: high · CVSS 7.2 · Published 1991-05-23

Executive brief

A vulnerability in the login component of AT&T System V Release 4 allows local users to bypass security restrictions and gain elevated system privileges. This could allow an individual with basic access to the system to take full control, potentially leading to the theft of sensitive data or disruption of operations. The issue affects older Unix-based systems used in legacy enterprise environments.

Technical details

A privilege escalation vulnerability exists in the 'login' executable of AT&T System V Release 4 (SVR4). The flaw allows a local user with shell access to exploit the login process to gain unauthorized elevated privileges, potentially reaching root-level access. The vulnerability is categorized as a local attack vector requiring no prior authentication beyond initial system access. While specific technical details regarding the root cause (e.g., buffer overflow or environment variable manipulation) are not detailed in the historical record, the impact is a complete compromise of confidentiality, integrity, and availability. Patches were historically issued by vendors such as AT&T and through CERT advisories in the early 1990s.

Affected products

  • AT&T System V Release 4 SVR4

Timeline

  • 1991-05-23: disclosed: Initial disclosure and NVD publication
  • 1991-12-31: advisory: Included in CERT 1991 annual advisory summary

References

Related threats