Junglewise Threat Intelligence

CVE-1999-1415: DEC ULTRIX privilege escalation in /usr/bin/mail

CVE-1999-1415 · Severity: medium · CVSS 4.6 · Published 1991-08-23

Technologies: Digital Ultrix. Vendors: Digital.

Executive brief

A vulnerability in the mail utility of the DEC ULTRIX operating system allows local users to gain unauthorized elevated privileges. This could allow a standard user to access sensitive system files or perform administrative actions, potentially compromising the entire server. The issue affects older versions of the ULTRIX operating system prior to version 4.2.

Technical details

A vulnerability exists in the /usr/bin/mail binary in DEC ULTRIX versions prior to 4.2. The flaw allows a local, authenticated user to exploit the mail utility to escalate their privileges on the system. While the specific mechanism (e.g., race condition or buffer overflow) is not detailed in the legacy advisory, the impact is a compromise of confidentiality, integrity, and availability. The issue was addressed in DEC ULTRIX version 4.2.

Affected products

  • DEC ULTRIX before 4.2

Timeline

  • 1991-08-23: advisory: NVD published date
  • 1991-08-23: disclosed: Original CERT advisory date

References

Related threats