cbcvebase.
CVE-1999-0046
published 1997-02-06

CVE-1999-0046: Buffer overflow of rlogin program using TERM environmental variable.

PriorityP346critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
51.88%
98.8th percentile
Buffer overflow of rlogin program using TERM environmental variable.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
bsdibsd_os
bsdibsd_os
bsdibsd_os
bsdibsd_os
debiandebian_linux
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
hphp-ux
hphp-ux
hphp-ux
hphp-ux
hphp-ux
hphp-ux
hphp-ux
hphp-ux
hphp-ux
hphp-ux
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix

Detection & IOCsextracted from sources · hover to see the quote

path/usr/bsd/rlogin
commandTERM=<overflow buffer with NOP sled and shellcode>
bytes
\x24\x0f\x12\x34
  • Detect MIPS IRIX shellcode NOP sled pattern: repeated 4-byte sequence 0x240f1234 in the TERM environment variable passed to rlogin.
  • The exploit targets the SUID rlogin binary; alert on rlogin spawning a shell (/bin/sh) as root, indicating successful privilege escalation.
  • Look for the LAST STAGE OF DELIRIUM exploit signature string in process environment or memory: 'copyright LAST STAGE OF DELIRIUM oct 1997 poland //lsd-pl.net/'
  • ·The exploit specifically targets IRIX 5.2, 5.3, 6.2, 6.3 on specific IP hardware platforms; the hardcoded address offset (jump()+10288+7000) is platform-specific and will not work on other architectures without modification.
  • ·The vulnerability was later updated to include additional IRIX versions; detection rules should not be limited to the originally listed platforms.
  • ·Similar buffer overflow bugs exist in some telnetd implementations via the TERM variable; detection logic for oversized TERM values should be applied to telnetd as well.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.