Junglewise Threat Intelligence

CVE-1999-1194: Digital Ultrix privilege escalation in chroot

CVE-1999-1194 · Severity: high · CVSS 7.2 · Published 1991-05-01

Technologies: Digital Ultrix. Vendors: Digital.

Executive brief

A security flaw in the Digital Ultrix operating system allows local users to bypass security restrictions. By exploiting an improperly installed system utility, a user with limited access can gain full administrative control over the system. This could lead to unauthorized access to sensitive data, system-wide outages, or complete compromise of the server.

Technical details

The chroot utility in Digital Ultrix versions 4.0 and 4.1 is improperly installed, leading to a privilege escalation vulnerability. While the specific mechanism (such as setuid bits or directory permissions) is not detailed in the legacy advisory, the flaw allows a local attacker to break out of restricted environments or manipulate the system to gain root access. This is a local attack requiring no special authentication beyond initial system access. The vulnerability was originally identified in 1991 and is addressed in subsequent vendor patches or version upgrades.

Affected products

  • Digital Ultrix 4.0, 4.1

Timeline

  • 1991-05-01: disclosed: Initial disclosure of the vulnerability
  • 1991-05-01: advisory: CERT advisory CA-1991-05 released

References