VYPR
Unrated severityNVD Advisory· Published Sep 23, 1999· Updated Apr 16, 2026

CVE-1999-1013

CVE-1999-1013

Description

AIX named-xfer allows system group members to overwrite files and gain root access via -f and malformed zone file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

AIX named-xfer allows system group members to overwrite files and gain root access via -f and malformed zone file.

Vulnerability

CVE-1999-1013 describes a vulnerability in the named-xfer utility included with AIX versions 4.1.5 and 4.2.1. The bug allows members of the system group to overwrite arbitrary system files by using the -f parameter and providing a malformed zone file [1]. The named-xfer program is used for zone transfers and runs with elevated privileges; the flaw arises from insufficient validation of the target file path when writing zone data.

Exploitation

An attacker must be a member of the system group on the target AIX system. The attack involves invoking named-xfer with the -f flag pointing to a system file (e.g., a configuration file) and supplying a purposely malformed zone file as input. No network access beyond local system group membership is required; the attacker can craft the zone file to cause named-xfer to overwrite the specified file [1].

Impact

Successful exploitation allows the attacker to overwrite any system file that named-xfer can write to. By overwriting critical files (e.g., replacing /etc/passwd or a configuration file), the attacker can escalate privileges to root, gaining full control of the system [1].

Mitigation

IBM has acknowledged the vulnerability in the referenced Bugtraq post from 1999 [1]. The recommended mitigation is to apply AIX patches or upgrade to a version that addresses the issue. For AIX 4.1.5 and 4.2.1, administrators should restrict membership in the system group and monitor usage of named-xfer until a fix is deployed.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • IBM/Aix3 versions
    cpe:2.3:o:ibm:aix:4.1.5:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:ibm:aix:4.1.5:*:*:*:*:*:*:*
    • cpe:2.3:o:ibm:aix:4.2.1:*:*:*:*:*:*:*
    • (no CPE)range: >=4.1.5,<=4.2.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.