PT-1992-1008 · Sun · Sunos
Published
1992-05-27
·
Updated
2017-10-10
·
CVE-1999-1142
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SunOS versions 4.1.2 and earlier
Description
The issue allows local users to gain privileges via
LD * environmental variables to certain dynamically linked setuid or setgid programs, such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.Recommendations
For SunOS versions 4.1.2 and earlier, consider restricting access to the dynamically linked setuid or setgid programs such as login, su, or sendmail until a fix is available. As a temporary workaround, avoid using the
LD * environmental variables in these programs to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sunos