Junglewise Threat Intelligence

CVE-1999-1487: IBM AIX privilege escalation in digest utility

CVE-1999-1487 · Severity: high · CVSS 7.2 · Published 1998-01-21

Technologies: IBM Aix. Vendors: IBM.

Executive brief

A vulnerability in the IBM AIX operating system allows users with print queue permissions to gain full administrative control over the system. By exploiting the 'digest' utility, an attacker can create or modify any file on the server, including sensitive system configuration files. This could lead to a complete compromise of the system's data and operations.

Technical details

The 'digest' utility in IBM AIX 4.3 contains a flaw that allows users belonging to the 'printq' group to escalate their privileges to root. The vulnerability stems from improper file handling or permission management within the utility, which enables an attacker to create or modify arbitrary files across the filesystem. By targeting critical system files (such as /etc/passwd or configuration files), a local attacker can achieve full root execution. The attack requires local access and existing print queue permissions. IBM has historically addressed this via APARs, though the original advisory links are now archived.

Affected products

  • IBM AIX 4.3

Timeline

  • 1998-01-21: disclosed: Initial publication date

References

Related threats