CVE-1999-0315: Buffer Overflow

Published Apr 1, 1997
·
Updated

Buffer overflow in Solaris fdformat command gives root access to local users.

Affected Software

9 affected components
Sun SunOS=5.3
Sun Solaris=2.4
Sun Solaris=2.5.1
Sun Solaris=2.5
Sun SunOS=5.7
Sun SunOS=5.5
Sun SunOS=5.4
Sun SunOS=5.5.1
Sun Solaris=2.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Oracle Solaris fdformat command from your environment.

    Uninstall or remove the fdformat binary from systems where it is not required until a vendor fix is provided.

  2. Configuration

    Disable or restrict execution of the fdformat command for non-administrative/local users (for example, remove execute permissions or otherwise prevent untrusted users from running the binary) until a vendor patch is available.

    Solaris fdformat execution_by_local_users = disabled or restricted
  3. Compensating control

    Restrict local account access and privileges on affected Oracle Solaris / SunOS systems (limit who can log in locally, enforce least privilege and isolate affected hosts from untrusted users) until the vulnerability is remediated.

  4. Operational

    Monitor for signs of local privilege escalation and, if compromise is suspected, perform incident response actions such as restoring from known-good backups, rebuilding affected hosts, and rotating credentials.

Event History

Apr 1, 1997
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Sep 29, 1999
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0315?

CVE-1999-0315 is classified as a critical vulnerability due to its ability to grant root access to local users.

2

How do I fix CVE-1999-0315?

To fix CVE-1999-0315, apply the relevant patches provided by the vendor for the affected Solaris and SunOS versions.

3

Who is affected by CVE-1999-0315?

CVE-1999-0315 affects users of Solaris versions 2.4, 2.5, 2.6, and SunOS versions 5.3 to 5.7.

4

Can CVE-1999-0315 be exploited remotely?

CVE-1999-0315 cannot be exploited remotely; it requires local access to the affected system.

5

What systems are vulnerable to CVE-1999-0315?

Vulnerable systems include Solaris running on SPARC and x86 architectures as well as certain versions of SunOS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203