CVE-1999-0773: Buffer Overflow
Buffer overflow in Solaris lpset program allows local users to gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
lpset (Oracle Solaris)from your environment.Uninstall or remove the vulnerable lpset program from affected Solaris systems if it is not required. If the program is required, restrict its presence to controlled systems and replace it with a patched version as soon as one is published.
- Compensating control
Restrict untrusted local user access: remove or disable unnecessary local accounts, restrict shell/login access, and limit physical/console access to trusted administrators to prevent unprivileged users from exercising the vulnerability.
- Operational
Audit systems for signs of local privilege escalation and compromise. If compromise is suspected, rotate root and other privileged credentials, investigate and restore affected systems from known-good backups, and apply the vendor fix when it becomes available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0773?
CVE-1999-0773 is considered a critical vulnerability due to its potential to allow local users to gain root access.
How do I fix CVE-1999-0773?
To fix CVE-1999-0773, you should apply the latest patches released by Oracle for Solaris versions that are affected.
What systems are affected by CVE-1999-0773?
CVE-1999-0773 affects Solaris 2.6, Solaris 7.0, and SunOS operating systems.
Can CVE-1999-0773 be exploited remotely?
CVE-1999-0773 cannot be exploited remotely since it requires local user access to trigger the buffer overflow.
Who is vulnerable to CVE-1999-0773?
Local users on affected Solaris and SunOS systems are vulnerable to CVE-1999-0773.