Junglewise Threat Intelligence

CVE-1999-1471: BSD passwd buffer overflow in shell or GECOS field

CVE-1999-1471 · Severity: high · CVSS 7.2 · Published 1989-01-01

Vendors: Bsd.

Executive brief

A vulnerability exists in the password management utility of older BSD-based operating systems. A local user with a standard account could exploit this flaw to gain full administrative (root) control over the system. This could lead to a complete compromise of the server, including unauthorized access to all data and the ability to disrupt operations.

Technical details

A buffer overflow vulnerability exists in the 'passwd' command of BSD-based operating systems version 4.3 and earlier. The flaw is triggered when the utility handles excessively long inputs for the user's shell path or the GECOS (user information) field. Because 'passwd' typically runs with setuid root privileges to modify system files, an attacker can exploit this overflow to overwrite the stack and execute arbitrary code with elevated privileges. This is a local exploit requiring an existing shell on the system. Patches were historically issued by vendors like Sun and DEC following the original 1989 CERT advisory.

Affected products

  • BSD BSD Operating System 4.3 and earlier

Timeline

  • 1989-01-01: disclosed: Original CERT advisory CA-1989-01 published
  • 1989-01-01: advisory: NVD published date

References