CVE-1999-0139: Buffer Overflow
Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Oracle Solaris mkcookiefrom your environment.If mkcookie is not required, remove or uninstall the mkcookie binary from affected Solaris x86 systems to eliminate the vulnerable program.
- Configuration
Until a vendor patch is available, restrict execution of the mkcookie binary (for example, remove execute permission for non-root users or remove the setuid bit / restrict ownership to root) so local unprivileged users cannot run it.
mkcookie (Solaris x86) execution permission = disabled for non-root users - Compensating control
Restrict local access and logins to affected systems (use host-based access controls, PAM, or ACLs) and block untrusted local accounts from executing administrative binaries until the vulnerability is remediated.
- Operational
Audit affected systems for signs of local privilege escalation; if compromise is suspected, isolate the host, rebuild or restore from known-good media, and rotate any credentials or keys that may have been exposed by root compromise.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0139?
CVE-1999-0139 has a high severity level due to its potential to allow local users to gain root access.
How do I fix CVE-1999-0139?
To fix CVE-1999-0139, apply the appropriate patches provided by Oracle for affected Solaris versions.
What versions of Solaris are affected by CVE-1999-0139?
CVE-1999-0139 affects Solaris versions 2.5, 2.5.1, and 7.0 on x86 architecture.
What is the nature of the vulnerability in CVE-1999-0139?
CVE-1999-0139 is a buffer overflow vulnerability that can be exploited to obtain root access.
Can CVE-1999-0139 be exploited remotely?
CVE-1999-0139 is a local vulnerability and cannot be exploited remotely.