CVE-1999-0023

inet rdist - Local Privilege Escalation via lookup() Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0023. PoCs published by Jeff Uphoff.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in rdist, a program for maintaining identical file copies across hosts. The PoC uses a crafted buffer with NOP sleds and shellcode to execute '/bin/sh' as root, leveraging the setuid bit on rdist in some environments.

Description

Local user gains root privileges via buffer overflow in rdist, via lookup() function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jeff Uphoff · clocallinux
https://www.exploit-db.com/exploits/19106

This exploit targets a buffer overflow vulnerability in rdist, a program for maintaining identical file copies across hosts. The PoC uses a crafted buffer with NOP sleds and shellcode to execute '/bin/sh' as root, leveraging the setuid bit on rdist in some environments.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: rdist (version not specified)
No auth needed
Prerequisites: rdist installed with setuid root · ability to execute rdist on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0023

Scores

EPSS 0.0077
EPSS Percentile 51.2%

Details

Status published
Products (28)
bsdi/bsd_os
freebsd/freebsd 2.0
freebsd/freebsd 2.0.5
freebsd/freebsd 2.1.0
freebsd/freebsd 2.2
ibm/aix 3.2
ibm/aix 4.1
ibm/aix 4.2
inet/inet 5.01
inet/inet 6.01
... and 18 more
Published Jul 24, 1996
Tracked Since Feb 18, 2026