CVE-1999-1408

HP-UX 10.01 and 9.05 - Denial of Service via Socket Reuse

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-1408. PoCs published by Cahya Wirawan.

AI-analyzed exploit summary This exploit targets a vulnerability in AIX and HP/UX systems where a sequence of two connect system calls to specific ports causes a system reboot. The PoC uses Perl to establish connections to ports 23 and 24 on localhost, triggering the flaw.

Description

Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Cahya Wirawan · perldoshp-ux
https://www.exploit-db.com/exploits/19278

This exploit targets a vulnerability in AIX and HP/UX systems where a sequence of two connect system calls to specific ports causes a system reboot. The PoC uses Perl to establish connections to ports 23 and 24 on localhost, triggering the flaw.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: AIX and HP/UX (specific versions not specified)
No auth needed
Prerequisites: Network access to the target system · Perl environment
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/352
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=87602167420641&w=2

Scores

EPSS 0.0101
EPSS Percentile 58.7%

Details

Status published
Products (9)
hp/hp-ux 9.05
hp/hp-ux 10.01
hp/hp-ux 10.20
ibm/aix 4.1
ibm/aix 4.1.1
ibm/aix 4.1.2
ibm/aix 4.1.3
ibm/aix 4.1.4
ibm/aix 4.1.5
Published Mar 05, 1997
Tracked Since Feb 18, 2026