CVE-1999-0687

ToolTalk ttsession - Command Injection

Title source: llm
STIX 2.1

Description

The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.

References (4)

Core 4
Core References
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/k-001.shtml
Various Sources vendor-advisory x_refsource_hp
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103
Vendor Advisory vendor-advisory x_refsource_sun
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/192
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/637

Scores

EPSS 0.0730
EPSS Percentile 91.8%

Details

Status published
Products (33)
cde/cde 1.0.1
cde/cde 1.0.2
cde/cde 1.1
cde/cde 1.2
cde/cde 2.0
cde/cde 2.1
cde/cde 2.120
digital/unix 4.0d
digital/unix 4.0f
ibm/aix 4.1
... and 23 more
Published Sep 13, 1999
Tracked Since Feb 18, 2026