Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-1999-0101Improper Restriction of Operations within the Bounds of a Memory Buffer in IBM AIX

4 documents4 sources
Severity
10.0CRITICALNVD
EPSS
3.9%
top 11.78%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedDec 10
Latest updateApr 30

Description

Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDibm/aix3.2, 4.1, 4.2+2

🔴Vulnerability Details

2
GHSA
GHSA-2q9f-93v8-w2pf: Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names2022-04-30
CVEList
CVE-1999-0101: Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names2000-01-18

💥Exploits & PoCs

1
Exploit-DB
AIX 3.x/4.x / Windows 95/98/2000/NT 4.0 / SunOS 5 - 'gethostbyname()' Remote Buffer Overflow2006-09-28
CVE-1999-0101 — IBM AIX vulnerability | cvebase