CVE-1999-0073Disclosure(digital / irix)

LOWCVSS 10.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch digital irix systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.

2.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • irix
  • osf_1
  • unix

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
irixosf_1unix

18 versions affected across 3 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-27: 1Mentions · 2026-03-05: 1PoC Mentioned / Linked · 2026-02-24: 1Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-24: 2Technical Details · 2026-03-05: 102-2402-2703-05
Signal classification3 categories
Disclosure
250.0%
PoC
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1PoC1
2026-02-271
Patch1
2026-03-051
Disclosure1
Full discourse4 posts
  • NanoVMs@nanovms
    Patch

    a 27 year old regression of CVE-1999-0073 now has a new cve CVE-2026-28372 (this is a new/diff one than from jan) the lesson here is not "jUsT Us# sSh!!!@" 1) ban users 2) ban shells 3) use unikernels https://t.co/hGMbYphRRi

    Post summary

    The post announces a new CVE and offers mitigations such as banning users and shells or using unikernels, but provides no PoC, exploit code, or technical details about the vulnerability.

    03061410
    2.0K followersView on X
  • Open Source Security mailing list@oss_security
    PoC

    Telnetd Vulnerability Report https://www.openwall.com/lists/oss-security/2026/02/24/2 Rediscoveries in InetUtils beyond last month's froot. Incomplete fix of CVE-1999-0073, where the CVE description's example was LD_LIBRARY_PATH, but new LPE PoCs use CREDENTIALS_DIRECTORY and GCONV_PATH. Avoided in Linux NetKit?

    Post summary

    The post reports that CVE-1999-0073 still has an incomplete fix and that new local privilege escalation PoCs using CREDENTIALS_DIRECTORY and GCONV_PATH have been discovered.

    02160770
    4.4K followersView on X
  • Morty@MortyJin
    Disclosure

    GCONV_PATH Injection in GNU Inetutils telnetd Credit: Discovered by Justin Swartz Reference: https://seclists.org/oss-sec/2026/q1/199 Justin revealed that while CVE-2026-24061 fix addressed the "-f root" authentication bypass, the underlying environment variable sanitization issue remains incomplete. Technical Details: ▪️ telnetd's scrub_env() blacklist misses GCONV_PATH, LANGUAGE, OUTPUT_CHARSET ▪️ When telnetd (running as root) execs /bin/login, AT_SECURE=0 ▪️ glibc doesn't sanitize these dangerous variables ▪️ gettext triggers iconv_open() → loads malicious .so via GCONV_PATH ▪️ Result: Arbitrary code execution as root Timeline: 1999: CVE-1999-0073 disclosed 2026: CVE-2026-24061 patched (USER variable injection) 2026-Feb: Justin Swartz discloses GCONV_PATH vector still exploitable #Security #Infosec #CVE #Linux #Telnetd #PrivilegeEscalation

    Post summary

    Justin Swartz disclosed that GCONV_PATH injection in GNU Inetutils telnetd remains exploitable, enabling arbitrary root code execution, despite the earlier patch for CVE‑2026‑24061.

    11040190
    121 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Telnet 脆弱性 CVE-2026-24061:27年前の問題の再発による root アクセス https://iototsecnews.jp/2026/02/26/27-years-old-telnet-vulnerability-enables-attackers-to-gain-root-access/ GNU Inetutils に含まれる telnet daemon (telnetd) において、27年前の脆弱性が現代に再燃するという事態が確認されました。この脆弱性 CVE-2026-24061 は、認証を一切必要とせずにリモートからの root 権限取得を、攻撃者に許すというきわめて深刻なものです。問題の核心は、1999年に発見された脆弱性 CVE-1999-0073 と同じく、環境変数の不適切なサニタイズにあります。telnetd がログイン処理のために “/bin/login” を起動する際に、特定の環境変数を無防備に受け入れてしまう設計上の欠陥が残存していました。ご利用のチームは、ご注意ください。 #CVE202624061 #telnet #Vulnerability

    Post summary

    The article announces that CVE‑2026‑24061, a 27‑year‑old vulnerability in GNU Inetutils telnetd, has resurfaced, permitting unauthenticated remote users to obtain root access via unsanitized environment variables.

    01000143
    483 followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
OSdigitalosf_11.2--
OSdigitalosf_11.3--
OSdigitalosf_12.0--
OSdigitalosf_13.0--
OSdigitalosf_13.2--
OSdigitalunix3.2g--
OSdigitalunix4.0--
OSsgiirix5.0--
OSsgiirix5.0.1--
OSsgiirix5.1--
OSsgiirix5.1.1--
OSsgiirix5.2--
OSsgiirix5.3--
OSsgiirix5.3--
OSsgiirix6.0--
OSsgiirix6.0.1--
OSsgiirix6.0.1--
OSsgiirix6.1--
OSsgiirix6.2--
OSsgiirix6.3--

Explore more