Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-1999-1208 โ€” Improper Restriction of Operations within the Bounds of a Memory Buffer in IBM AIX

4 documents4 sources
Severity
7.2HIGHNVD
EPSS
3.8%
top 11.94%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 21
Latest updateApr 30

Description

Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

โ–ถNVDibm/aix3.2.5, 4.1, 4.2+2

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-h664-4mr2-whv6: Buffer overflow in ping in AIX 4โ†—2022-04-30
โ–ถ
CVEList
CVE-1999-1208: Buffer overflow in ping in AIX 4โ†—2002-03-09
โ–ถ

๐Ÿ’ฅExploits & PoCs

1
Exploit-DB
IBM AIX 4.2 - 'ping' Local Buffer Overflowโ†—1997-07-21
โ–ถ
CVE-1999-1208 โ€” IBM AIX vulnerability | cvebase