CVE-1999-1008

xsoldier - Privilege Escalation via Long Argument

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-1999-1008. PoCs published by zorgon, Larry W. Cashdollar, Brock Tellier.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in xsoldier-0.96 on Red Hat Linux 6.2 (Zoot). It uses a NOP sled and shellcode to achieve remote code execution by overflowing the buffer and overwriting the return address.

Description

xsoldier program allows local users to gain root access via a long argument.

Exploits (3)

exploitdb WORKING POC VERIFIED
by zorgon · clocallinux
https://www.exploit-db.com/exploits/229

This exploit targets a buffer overflow vulnerability in xsoldier-0.96 on Red Hat Linux 6.2 (Zoot). It uses a NOP sled and shellcode to achieve remote code execution by overflowing the buffer and overwriting the return address.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: xsoldier-0.96 on Red Hat Linux 6.2 (Zoot)
No auth needed
Prerequisites: Target must be running xsoldier-0.96 on Red Hat Linux 6.2 (Zoot) · Attacker must be able to pass a malicious buffer to the '-display' argument
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Larry W. Cashdollar · clocallinux
https://www.exploit-db.com/exploits/19677

This exploit targets a buffer overflow vulnerability in the xsoldier game (setuid root) on FreeBSD 3.3 and Linux Mandrake. It overflows the -display option with a crafted buffer containing NOPs, shellcode, and a manipulated return address to execute arbitrary code with root privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: xsoldier (X11 games package) on FreeBSD 3.3 and Linux Mandrake
No auth needed
Prerequisites: xsoldier binary installed as setuid root · ability to execute the binary
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Brock Tellier · clocallinux
https://www.exploit-db.com/exploits/19676

This exploit targets a buffer overflow vulnerability in the xsoldier binary (part of X11 games) on FreeBSD 3.3-RELEASE and Linux Mandrake. It leverages a long string supplied to the -display option to overwrite the return address and execute shellcode that drops a suid root shell in /bin/sh.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: xsoldier (X11 games package) on FreeBSD 3.3-RELEASE and Linux Mandrake
No auth needed
Prerequisites: xsoldier binary must be setuid root · Target system must be FreeBSD 3.3-RELEASE or Linux Mandrake with vulnerable xsoldier
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/871

Scores

EPSS 0.0073
EPSS Percentile 49.5%

Details

Status published
Products (2)
freebsd/freebsd 3.3
mandrakesoft/mandrake_linux 7.0
Published May 17, 2000
Tracked Since Feb 18, 2026