CVE-1999-0132: Low severity Sun SunOS vulnerability
Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
expreserve (used by vi and ex)from your environment.Remove or uninstall the expreserve component from affected systems (HPE HP-UX, Oracle Solaris/ZFS, SunOS). If removal is not possible, replace or rebuild the vi/ex binaries so they do not include or invoke expreserve.
- Configuration
Reconfigure, rebuild, or replace vi and ex so that they do not invoke or use expreserve; disable any feature in these editors that relies on expreserve until a vendor fix is available.
vi/ex (expreserve) expreserve usage = disabled - Compensating control
Restrict local account access and limit who can execute vi/ex on affected hosts (apply host-based access controls, restrict shell access to trusted administrators, and monitor local activity) until an official patch or vendor remediation is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0132?
CVE-1999-0132 is considered a high severity vulnerability due to its ability to allow local users to gain root access.
How do I fix CVE-1999-0132?
To fix CVE-1999-0132, you should upgrade to the latest version of the affected software that addresses this vulnerability.
Who is affected by CVE-1999-0132?
CVE-1999-0132 affects users of certain versions of SunOS and HP-UX operating systems.
What are the risks associated with CVE-1999-0132?
The risks associated with CVE-1999-0132 include unauthorized file overwriting and complete system compromise.
What is the impact of CVE-1999-0132?
The impact of CVE-1999-0132 can lead to root access for local users, allowing them to control the system and access sensitive data.