CVE-1999-0295: High severity Sun SunOS vulnerability

Published Oct 1, 1997
·
Updated

Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.

Affected Software

8 affected components
Sun SunOS=5.3
Sun Solaris=2.4
Sun Solaris=2.5.1
Sun Solaris=2.5.1
Sun Solaris=2.5
Sun SunOS=5.5
Sun SunOS=5.4
Sun SunOS=5.5.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Oracle Solaris sysdef from your environment.

    If sysdef is not required, remove or uninstall the sysdef binary from affected systems to eliminate the ability for local users to read kernel memory.

  2. Configuration

    Restrict the sysdef binary so only root can execute it (e.g., chown root:root /path/to/sysdef && chmod 700 /path/to/sysdef) to prevent local non-privileged users from running it.

    sysdef command (Solaris) file_permissions = owner=root, permissions=0700
  3. Compensating control

    Limit local account and administrative access: disable or remove unneeded local accounts, restrict who can obtain interactive shells, and apply the principle of least privilege so only trusted administrators can access affected systems.

  4. Operational

    Audit systems for the presence and recent execution of sysdef, review logs for suspicious activity, and investigate any indications of compromise (including potential privilege escalation). If compromise is suspected, follow incident response procedures (containment, eradication, recovery).

Event History

Oct 1, 1997
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 29, 1999
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0295?

CVE-1999-0295 is classified as a high severity vulnerability due to potential unauthorized access to kernel memory.

2

How do I fix CVE-1999-0295?

To fix CVE-1999-0295, ensure that systems are updated to the latest security patches provided by Oracle.

3

What systems are affected by CVE-1999-0295?

CVE-1999-0295 affects several versions of Solaris and SunOS, specifically 5.3, 2.4, and other specified versions.

4

Can CVE-1999-0295 allow an attacker to gain root privileges?

Yes, CVE-1999-0295 can potentially allow local users to read kernel memory, which may lead to obtaining root privileges.

5

Is there a workaround for CVE-1999-0295?

The most effective workaround for CVE-1999-0295 is to limit access to the sysdef command or to apply the relevant security patches immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203