PT-1997-1234 · Sun · Solaris+1
Published
1997-05-17
·
Updated
2018-10-30
·
CVE-1999-1402
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Solaris versions 2.x
SunOS versions 4.x and earlier than 4.4
Description
The issue concerns ignored access permissions for a UNIX domain socket in certain operating systems, potentially allowing local users to connect to the socket. This could disrupt or control the operations of the program using that socket.
Recommendations
For Solaris 2.x, consider restricting access to the UNIX domain socket to minimize the risk of exploitation.
For SunOS 4.x and earlier than 4.4, restrict access to the UNIX domain socket until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solaris
Sunos