Junglewise Threat Intelligence

CVE-1999-1186: rxvt privilege escalation via -print-pipe argument

CVE-1999-1186 · Severity: high · CVSS 7.2 · Published 1996-01-02

Technologies: Slackware Linux, Redhat Linux. Vendors: Slackware, Redhat.

Executive brief

rxvt is a terminal emulator used in older Linux distributions to provide a command-line interface within a graphical environment. A vulnerability exists where the program fails to drop administrative (root) privileges before executing a user-defined printing command. A local user with access to the system can exploit this to run any command with full administrative rights, leading to a complete takeover of the machine.

Technical details

The rxvt terminal emulator, when compiled with the PRINT_PIPE option and installed with the setuid root bit (often required for utmp logging), fails to drop privileges before invoking a pipe to a printer command. An attacker can use the '-print-pipe' command-line argument to specify an arbitrary executable instead of the intended printer utility. By sending the VT100 'printer-on' escape sequence (ESC[5i) to the terminal, the attacker triggers a popen() call that executes the malicious program with root privileges. This vulnerability affects early Linux distributions like Slackware 3.0 and RedHat 2.1. A temporary mitigation is to remove the setuid bit from the rxvt binary.

Affected products

  • rxvt project rxvt Slackware 3.0, RedHat 2.1, and other systems where rxvt is suid root

Timeline

  • 1996-01-02: disclosed: Initial bugtraq disclosure by David J Meltzer
  • 1996-01-02: advisory: NVD published date

References

Related threats