CVE-1999-0712: Low severity Caldera COAS vulnerability

Published Apr 27, 1999
·
Updated

A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.

Affected Software

4 affected components
Caldera COAS=1.0.5
Caldera COAS=1.0.6
Caldera COAS=1.0.7
Caldera OpenLinux=2.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Caldera Open Administration System (COAS) from your environment.

    If COAS is not required, uninstall or decommission it from affected systems to eliminate the attack vector.

  2. Configuration

    Ensure /etc/shadow is owned by root:root and set to mode 600 (e.g., chown root:root /etc/shadow && chmod 600 /etc/shadow) to prevent it from being world-readable.

    /etc/shadow (Linux) file permissions and ownership = 600, owner: root, group: root
  3. Compensating control

    Until a vendor patch is available or the software is removed, isolate the affected host(s) (network segmentation) and restrict administrative/management access to trusted IPs (firewall/ACL) to reduce exposure.

  4. Operational

    After restoring correct permissions, rotate all local account passwords and any credentials that may have been exposed via /etc/shadow.

Event History

Apr 27, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-0712?

CVE-1999-0712 has a high severity rating due to the potential exposure of sensitive password information.

2

How do I fix CVE-1999-0712?

To fix CVE-1999-0712, ensure that the /etc/shadow file permissions are securely set to restrict access.

3

Which versions of Caldera COAS are affected by CVE-1999-0712?

CVE-1999-0712 affects Caldera COAS versions 1.0.5, 1.0.6, and 1.0.7.

4

What impact does CVE-1999-0712 have on system security?

CVE-1999-0712 can allow unauthorized users to read the /etc/shadow file, compromising user accounts and system security.

5

Is there a patch available for CVE-1999-0712?

There is no specific patch for CVE-1999-0712, but adjusting file permissions is a necessary mitigation step.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203