CVE-1999-0369: Buffer Overflow
The Sun sdtcmconvert calendar utility for OpenWindows has a buffer overflow which can gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
sdtcm_convert (OpenWindows calendar utility)from your environment.Uninstall or remove the sdtcm_convert utility from affected Oracle Solaris / SunOS systems if it is not required until an official fix is available.
- Configuration
Disable the OpenWindows calendar utility (sdtcm_convert) or disable OpenWindows calendar functionality on affected systems until a patch is released.
OpenWindows (sdtcm_convert calendar utility) enabled = false - Compensating control
Restrict access to the sdtcm_convert binary and limit local user access to affected systems until a fix is available (for example, remove execute permission for non-administrative users or restrict who can run the binary).
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0369?
CVE-1999-0369 is considered a high severity vulnerability due to its ability to gain root access.
How do I fix CVE-1999-0369?
To fix CVE-1999-0369, ensure that the Sun sdtcm_convert utility is updated to a patched version that mitigates the buffer overflow vulnerability.
Which systems are affected by CVE-1999-0369?
CVE-1999-0369 affects various versions of SunOS and Solaris, including versions 5.0 through 5.5 for SunOS and several Solaris versions.
What type of vulnerability is CVE-1999-0369?
CVE-1999-0369 is a buffer overflow vulnerability that can lead to unauthorized root access.
Is CVE-1999-0369 still relevant today?
While CVE-1999-0369 was identified a long time ago, it remains relevant for legacy systems still in use that have not been patched.