First published: Wed Dec 01 1999(Updated: )
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris SPARC | =2.5.1 | |
Oracle Solaris SPARC | =2.5.1 | |
Oracle Solaris SPARC | =2.6 | |
Oracle Solaris SPARC | =7.0 | |
Sun SunOS | ||
Sun SunOS | =5.5.1 | |
Sun SunOS | =5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0860 is classified as a high-severity vulnerability due to its potential for local privilege escalation.
To fix CVE-1999-0860, ensure that the VMSYS environmental variable is properly restricted to prevent symlink attacks.
CVE-1999-0860 affects Solaris versions 2.5.1, 2.6, 7.0, and various SunOS versions including 5.5.1 and 5.7.
Local users can exploit CVE-1999-0860 to gain unauthorized access to files owned by the 'bin' user.
The consequences of CVE-1999-0860 include unauthorized access to sensitive files, which can lead to further security breaches.