CVE-1999-0136: High severity Sun SunOS vulnerability
Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Kodak Color Management System (KCMS)from your environment.Uninstall the Kodak Color Management System (KCMS) from affected SunOS/Solaris systems if it is not required.
- Compensating control
Restrict local unprivileged user access to affected SunOS/Solaris hosts (disable or remove unneeded accounts, restrict shell/logon access to trusted administrators, and limit physical/console access) until KCMS is removed or a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0136?
CVE-1999-0136 has a high severity as it allows local users to gain root access.
How do I fix CVE-1999-0136?
To fix CVE-1999-0136, update the Kodak Color Management System to the latest version or apply relevant security patches.
Which systems are affected by CVE-1999-0136?
CVE-1999-0136 affects the SunOS versions 5.5 and 5.5.1.
What type of attack does CVE-1999-0136 enable?
CVE-1999-0136 enables local users to write to arbitrary files, potentially leading to privilege escalation.
Is CVE-1999-0136 a remote or local vulnerability?
CVE-1999-0136 is a local vulnerability, as it requires local user access to exploit.