CVE-1999-1486

IBM AIX <4.3 - Local Privilege Escalation

Title source: llm
STIX 2.1

Description

sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.

References (6)

Core 6
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=IX75554&apar=only
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=IX76330&apar=only
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/408
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7675
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=IX76853&apar=only

Scores

EPSS 0.0031
EPSS Percentile 22.9%

Details

Status published
Products (9)
ibm/aix 4.1
ibm/aix 4.1.1
ibm/aix 4.1.2
ibm/aix 4.1.3
ibm/aix 4.1.4
ibm/aix 4.1.5
ibm/aix 4.2
ibm/aix 4.2.1
ibm/aix 4.3
Published Feb 25, 1998
Tracked Since Feb 18, 2026