PT-1993-1011 · Sun · Sunos
Published
1993-09-17
·
Updated
2018-10-30
·
CVE-1999-1318
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SunOS versions 4.1.3 and earlier
Description
The issue allows local users to gain privileges via Trojan horse programs due to the search path used by /usr/5bin/su, which includes the current working directory.
Recommendations
For SunOS versions 4.1.3 and earlier, consider modifying the search path to exclude the current working directory or restrict access to the /usr/5bin/su command to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sunos