CVE-1999-1118: Low severity Sun Solaris vulnerability
ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Restrict access to the ndd utility so that only root or trusted administrative accounts can execute it, preventing local (unprivileged) users from modifying TCP/IP parameters.
ndd (Solaris 2.6) executable access = root-only - Compensating control
Restrict local account privileges and interactive logins to trusted administrators; apply host-based access controls (local ACLs/authorization) to prevent unprivileged local users from invoking ndd or otherwise modifying TCP/IP parameters.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1118?
CVE-1999-1118 is classified as a denial of service vulnerability.
How can I exploit CVE-1999-1118?
Exploitation of CVE-1999-1118 can occur when local users modify certain TCP/IP parameters, leading to service disruption.
How do I fix CVE-1999-1118?
To fix CVE-1999-1118, ensure that access to the ndd command is restricted to authorized users.
What systems are affected by CVE-1999-1118?
CVE-1999-1118 specifically affects Solaris 2.6 running on SPARC architecture.
Is there a patch available for CVE-1999-1118?
There is no specific patch mentioned for CVE-1999-1118, but restricting user access is recommended to mitigate the vulnerability.