PT-1997-1234 · Sun · Solaris+1

Published

1997-05-17

·

Updated

2018-10-30

·

CVE-1999-1402

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Solaris versions 2.x SunOS versions 4.x and earlier than 4.4
Description The issue concerns ignored access permissions for a UNIX domain socket in certain operating systems, potentially allowing local users to connect to the socket. This could disrupt or control the operations of the program using that socket.
Recommendations For Solaris 2.x, consider restricting access to the UNIX domain socket to minimize the risk of exploitation. For SunOS 4.x and earlier than 4.4, restrict access to the UNIX domain socket until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1402

Affected Products

Solaris
Sunos