CVE-1999-0825: Low severity SCO UnixWare vulnerability
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Change the permissions and/or ownership of /var/mail to prevent non-owner local users from reading or writing other users' mail (for example, adjust chmod/chown or set filesystem ACLs to remove world/group read/write access).
Xinuos UnixWare /var/mail directory permissions = restrict access so local users cannot read or modify other users' mail - Compensating control
If immediate permission changes are not possible, apply access controls (ACLs), filesystem mount options, or host-based restrictions to block local users from accessing other users' mail files in /var/mail until permissions are corrected.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0825?
CVE-1999-0825 has a moderate severity level due to the potential for local users to access and modify each other's mail.
How do I fix CVE-1999-0825?
To fix CVE-1999-0825, change the permissions on the /var/mail directory to restrict access to only the intended users.
What systems are affected by CVE-1999-0825?
CVE-1999-0825 affects Xinuos UnixWare versions 7.0, 7.0.1, and 7.1.
Who can exploit CVE-1999-0825?
Local users on the system can exploit CVE-1999-0825 due to the default permissive settings.
Is there a patch available for CVE-1999-0825?
There is no specific patch for CVE-1999-0825; instead, it is recommended to modify the directory permissions as a remediation step.