CVE-1999-0966: Buffer Overflow

Published Jan 27, 1997
·
Updated

Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].

Affected Software

1 affected component
Sun SunOS=5.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Temporarily remove or disable the setuid bit from non-essential setuid-root binaries (or otherwise prevent their execution) to reduce the risk that a local user can exploit the libc getopt overflow to gain root.

    SunOS setuid_binaries = disabled/removed for non-essential binaries
  2. Compensating control

    Restrict local user access: disable or remove unneeded local accounts, limit who can log in interactively, and restrict execution of untrusted binaries (use file system permissions, RBAC, or host-based policies) until an official fix is available.

  3. Operational

    Monitor and audit systems for signs of exploitation (suspicious processes, unexpected root activity, or unusually long argv[0] values). If compromise is suspected, assume root may be controlled: isolate the host, perform forensic analysis, rebuild or restore from known-good media, and rotate/root credentials.

Event History

Jan 27, 1997
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Mar 22, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0966?

CVE-1999-0966 has a high severity rating due to the potential for local users to gain root privileges.

2

How do I fix CVE-1999-0966?

To fix CVE-1999-0966, apply the appropriate patches provided by Sun Microsystems for SunOS 5.5.

3

What systems are affected by CVE-1999-0966?

CVE-1999-0966 affects systems running SunOS version 5.5.

4

Can CVE-1999-0966 be exploited remotely?

CVE-1999-0966 cannot be exploited remotely as it requires local access to the vulnerable system.

5

What impact does CVE-1999-0966 have on system security?

CVE-1999-0966 allows local users to execute arbitrary code with root privileges, posing a significant security risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203