CVE-1999-0442: Low severity Sun Solaris vulnerability
Solaris ff.core allows local users to modify files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict and harden local user access: remove or disable unnecessary local accounts, enforce least-privilege for local users, restrict interactive logins to trusted administrators (console/SSH), and limit account creation to authorized personnel.
- Operational
Audit and remediate potential file modifications: run file-integrity checks, compare against known-good backups, restore altered files as needed, and rotate any credentials, keys, or secrets that may have been stored in or accessible to the modified files.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0442?
CVE-1999-0442 is considered a high-severity vulnerability that allows local users to modify files.
How do I fix CVE-1999-0442?
To fix CVE-1999-0442, ensure that proper file permissions and user access controls are implemented.
Which versions of Solaris are affected by CVE-1999-0442?
CVE-1999-0442 affects Solaris versions 2.5, 2.5.1, 2.6, 7.0, along with various SunOS versions including 5.5, 5.5.1, and 5.7.
Can CVE-1999-0442 be exploited remotely?
CVE-1999-0442 is a local vulnerability, meaning it cannot be exploited remotely and requires local access to the system.
What types of systems should prioritize mitigating CVE-1999-0442?
Systems running vulnerable versions of Solaris and SunOS should prioritize mitigation of CVE-1999-0442 to prevent unauthorized file modifications.