CVE-1999-0134: High severity Sun SunOS vulnerability
vold in Solaris 2.x allows local users to gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SunOS/voldfrom your environment.Uninstall or remove the vold package if it is not required on the system.
- Configuration
Stop and disable the vold service until a vendor-supplied fix is available to prevent local users from exploiting this flaw to gain root.
vold (Solaris Volume Daemon) service state = disabled - Compensating control
Restrict local account usage and physical/console access: remove or disable unneeded local user accounts, enforce least-privilege for local users, and limit who can log in locally to reduce exposure to local privilege escalation.
- Operational
If there is any possibility the vulnerability was exploited, assume compromise: perform forensic analysis or rebuild systems from trusted media and rotate credentials for root and other privileged accounts.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0134?
CVE-1999-0134 has a high severity level as it allows local users to gain root access on affected Solaris systems.
How do I fix CVE-1999-0134?
To fix CVE-1999-0134, it is recommended to apply the latest security patches provided by Sun for Solaris versions 5.4 and 5.5.
Which versions of Solaris are affected by CVE-1999-0134?
CVE-1999-0134 affects Solaris versions 5.4, 5.5, and 5.5.1.
Can CVE-1999-0134 be exploited remotely?
CVE-1999-0134 is a local vulnerability, meaning it requires local user access to exploit.
What component is vulnerable in CVE-1999-0134?
The vulnerability in CVE-1999-0134 exists in the vold component of Solaris 2.x.