PT-1997-1239 · Oracle · Solaris Solstice Adminsuite
Published
1997-11-10
·
Updated
2008-09-05
·
CVE-1999-1424
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Solaris Solstice AdminSuite (AdminSuite) version 2.1
Description
The issue allows local users to gain root access by modifying their password table entries due to unsafe permissions when adding new users to the NIS+ password table.
Recommendations
For version 2.1, consider restricting access to the NIS+ password table to prevent local users from modifying their password table entries until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solaris Solstice Adminsuite