PT-1999-1002 · Sun Microsystems · Solaris

Published

1999-12-31

·

Updated

2024-09-17

·

CVE-1999-1587

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sun Microsystems Solaris versions 8 and 9, and certain earlier releases
Description The issue is related to insufficient protection of sensitive data in the /usr/ucb/ps component of the Solaris operating system. This allows local users to view the environment variables and values of arbitrary processes via the -e option. Exploitation of this issue may enable an attacker to access confidential information.
Recommendations For Sun Microsystems Solaris versions 8 and 9, and certain earlier releases, consider restricting access to the /usr/ucb/ps component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-11465
CVE-1999-1587

Affected Products

Solaris