CVE-1999-0120: High severity Sun Sunos vulnerability
Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Ensure the utmp file is owned by root and remove write permission for all non-root users so only root can write to it (i.e., change ownership to root and remove group/other write permissions).
SunOS/Solaris utmp file file permissions = not writable by users other than root
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0120?
CVE-1999-0120 is considered a high severity vulnerability as it allows local users to gain root access.
How do I fix CVE-1999-0120?
To fix CVE-1999-0120, ensure that the utmp file is not writable by users other than root.
What systems are affected by CVE-1999-0120?
CVE-1999-0120 affects various versions of Sun/Solaris, specifically SunOS 4.1 and other related versions.
Who can exploit CVE-1999-0120?
CVE-1999-0120 can be exploited by any local user who has access to the system.
What could happen if CVE-1999-0120 is exploited?
If CVE-1999-0120 is exploited, an attacker can gain root access, potentially allowing them complete control over the affected system.