CVE-1999-0135: High severity Sun Solaris vulnerability
admintool in Solaris allows a local user to write to arbitrary files and gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
admintool (Oracle Solaris)from your environment.Uninstall or remove admintool from systems where it is not required.
- Configuration
Restrict admintool so that only the root account can execute it (e.g., adjust file ownership and permissions to remove execute access for non-root users).
admintool (Oracle Solaris) access/executable = restrict to root only - Compensating control
Restrict local user access to affected systems and limit which accounts can log in or run administrative tools (use host-based access controls, SSH/console restrictions, or similar measures to prevent untrusted local users from reaching admintool).
- Operational
Audit systems where admintool was present for signs of unauthorized file writes or root access; if compromise is suspected, rotate credentials and keys, and restore affected files from trusted backups.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0135?
CVE-1999-0135 is considered a critical vulnerability due to its ability to allow local users to gain root access.
How do I fix CVE-1999-0135?
To fix CVE-1999-0135, ensure that you apply the appropriate security patches for Solaris versions 2.5, 2.5.1, and SunOS 5.5.
Who is affected by CVE-1999-0135?
CVE-1999-0135 affects local users on Solaris 2.5, 2.5.1, and SunOS 5.5 systems.
What systems are vulnerable to CVE-1999-0135?
The vulnerable systems include Solaris 2.5, 2.5.1 for both x86 and PPC architectures, as well as SunOS 5.5 and 5.5.1.
What impact does CVE-1999-0135 have on systems?
CVE-1999-0135 allows local users to write to arbitrary files, potentially leading to unauthorized root access and system compromise.