Junglewise Threat Intelligence

CVE-1999-1468: UNIX rdist privilege escalation via IFS variable manipulation

CVE-1999-1468 · Severity: medium · CVSS 6.2 · Published 1991-10-22

Technologies: Various Unix.

Executive brief

A vulnerability in the 'rdist' utility, a tool used on older UNIX systems to maintain identical copies of files across multiple hosts, could allow a local user to gain full administrative (root) control of the system. By manipulating how the system interprets command separators, an attacker can trick the utility into executing unauthorized programs with elevated privileges. This poses a significant risk to the integrity and confidentiality of the affected server.

Technical details

The 'rdist' utility in various UNIX distributions is vulnerable to a privilege escalation attack. The vulnerability exists because rdist uses the popen() function to execute sendmail for mailing status reports. Because popen() invokes the shell (/bin/sh) to execute the command, it is susceptible to IFS (Internal Field Separator) manipulation. A local attacker can modify the IFS environment variable to include a slash ('/') or other characters, causing the shell to misinterpret the path to sendmail and instead execute an arbitrary program with the root privileges of the setuid rdist binary. This is a classic shell metacharacter/environment manipulation vulnerability. Patching typically involves replacing popen() with safer alternatives like execve() or ensuring the environment is sanitized before execution.

Affected products

  • various UNIX

Timeline

  • 1991-10-22: disclosed
  • 1991-10-22: advisory

References