CVE-1999-1025: Medium severity Sun Sunos vulnerability
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
CDE screen lock program (screenlock)from your environment.Uninstall or disable the CDE screen lock program (screenlock) on affected Solaris 2.6 hosts to avoid the insecure lock behavior when the host is an NIS+ client.
- Configuration
Remove the host from NIS+ or disable the NIS+ client configuration so the system is not an NIS+ client (the issue occurs only when the host is an NIS+ client).
NIS+ client NIS+ client membership = disabled - Compensating control
Restrict physical access to the console (lock server rooms, limit console access to authorized personnel, and apply physical security controls) until a vendor fix or other permanent remediation is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1025?
CVE-1999-1025 is considered a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-1999-1025?
To fix CVE-1999-1025, ensure that the screen lock program is configured correctly or apply any available patches for Solaris 2.6.
Which systems are affected by CVE-1999-1025?
CVE-1999-1025 affects systems running Solaris 2.6, SunOS, and SunOS 5.6.
What are the risks associated with CVE-1999-1025?
The risks associated with CVE-1999-1025 include unauthorized access to user sessions by individuals with physical access to the console.
Is there a workaround for CVE-1999-1025?
A possible workaround for CVE-1999-1025 is to prevent physical access to the console or implement alternative security measures.