CVE-1999-0866: Buffer Overflow
Buffer overflow in UnixWare xauto program allows local users to gain root privilege.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Xinuos UnixWare xautofrom your environment.Uninstall or remove the xauto program from affected systems if it is not required.
- Configuration
Change filesystem permissions to prevent non-privileged local users from executing xauto (for example, remove execute permission for non-root accounts or restrict the file to root-only access).
xauto execution permission = disabled for non-root users - Compensating control
Restrict local user access to affected systems (limit who can obtain local/console/SSH shell access) and apply host-based access controls to prevent untrusted local accounts from running privileged programs.
- Operational
If exploitation is suspected, perform an investigation for root compromise, restore affected systems from known-good backups or rebuild, and rotate any credentials or keys that may have been exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0866?
CVE-1999-0866 is considered high severity due to the potential for local users to gain root privileges.
How do I fix CVE-1999-0866?
To fix CVE-1999-0866, ensure that you apply any available patches or updates for UnixWare versions 7.0, 7.0.1, 7.1, or 7.1.1.
Who is affected by CVE-1999-0866?
CVE-1999-0866 affects local users on UnixWare versions 7.0, 7.0.1, 7.1, and 7.1.1.
What type of vulnerability is CVE-1999-0866?
CVE-1999-0866 is a buffer overflow vulnerability in the xauto program of UnixWare.
Can CVE-1999-0866 be exploited remotely?
CVE-1999-0866 cannot be exploited remotely as it requires local access to the system.