Vulnerability Name:

CVE-1999-0691 (CCN-3241)

Assigned:1999-09-13
Published:1999-09-13
Updated:2018-10-30
Summary:Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: SGI Security Advisory 20011107-01-P
CDE vulnerabilities

Source: CCN
Type: SGI Security Advisory 20020302-01-A
Additional CDE and CDE ToolTalk Vulnerabilities

Source: CCN
Type: BugTraq Mailing List, Mon, 13 Sep 1999 16:04:35 +0200
Vulnerability in dtaction

Source: MITRE
Type: CNA
CVE-1999-0691

Source: CCN
Type: Compaq Services Software Patches SSRTO615U_DTACTION
SSRTO615U_DTACTION Potential Security Problem when using dtaction

Source: CCN
Type: Sun Microsystems, Inc. Security Bulletin #00185
Common Desktop Environment (CDE)

Source: SUN
Type: UNKNOWN
00192

Source: CCN
Type: Sun Microsystems, Inc. Security Bulletin #00192
CDE and OpenWindows

Source: CCN
Type: Hewlett-Packard Company Security Bulletin HPSBUX9909-103
Security Vulnerability in CDE ttsession (Rev.01)

Source: CCN
Type: IBM Technical Support Web site
AIX General Software Fixes

Source: CCN
Type: CERT Advisory CA-1999-11
Four Vulnerabilities in the Common Desktop Environment

Source: CCN
Type: ITSX Web site
dtaction hole

Source: CCN
Type: OSVDB ID: 1071
Multiple Vendor CDE dtaction AddSuLog Function Local Overflow

Source: BID
Type: UNKNOWN
635

Source: CCN
Type: BID-635
Multiple Vendor CDE dtaction Userflag Buffer Overflow Vulnerability

Source: HP
Type: UNKNOWN
HPSBUX9909-103

Source: XF
Type: UNKNOWN
cde-dtaction-username-bo(3241)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:3078

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cde:cde:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:cde:cde:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:cde:cde:1.1:*:*:*:*:*:*:*
  • OR cpe:/a:cde:cde:1.2:*:*:*:*:*:*:*
  • OR cpe:/a:cde:cde:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:cde:cde:2.1:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:digital:unix:4.0d:*:*:*:*:*:*:*
  • OR cpe:/o:digital:unix:4.0e:*:*:*:*:*:*:*
  • OR cpe:/o:digital:unix:4.0f:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.1:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.1.1:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.1.2:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.1.3:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.1.4:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.1.5:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.2:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.2.1:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.3:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.3.1:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:4.3.2:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:2.4:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:2.5.1:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.6:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:7.0:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.4:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.5:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.7:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:3078
    V
    CDE AddSuLog Function Buffer Overflow
    2005-03-09
    BACK
    cde cde 1.0.1
    cde cde 1.0.2
    cde cde 1.1
    cde cde 1.2
    cde cde 2.0
    cde cde 2.1
    digital unix 4.0d
    digital unix 4.0e
    digital unix 4.0f
    ibm aix 4.1
    ibm aix 4.1.1
    ibm aix 4.1.2
    ibm aix 4.1.3
    ibm aix 4.1.4
    ibm aix 4.1.5
    ibm aix 4.2
    ibm aix 4.2.1
    ibm aix 4.3
    ibm aix 4.3.1
    ibm aix 4.3.2
    sun solaris 2.4
    sun solaris 2.5.1
    sun solaris 2.6
    sun solaris 7.0
    sun sunos 5.4
    sun sunos 5.5
    sun sunos 5.5.1
    sun sunos 5.7