CVE-1999-1123: High severity Sun SunOS vulnerability
The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sun Source (sunsrc)from your environment.Uninstall the Sun Source (sunsrc) tapes or remove the installed sunsrc files to eliminate the vulnerable setuid root programs.
- Configuration
Remove the setuid permission from the makeinstall and winstall binaries (for example, run chmod u-s on each installed makeinstall and winstall) to prevent local users from gaining root via these programs.
makeinstall and winstall setuid = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1123?
CVE-1999-1123 is considered a critical vulnerability due to its potential to allow local users to gain root privileges.
How do I fix CVE-1999-1123?
To fix CVE-1999-1123, you should remove or restrict access to the affected setuid root programs such as makeinstall and winstall.
Which systems are affected by CVE-1999-1123?
CVE-1999-1123 affects SunOS versions 4.0.3, 4.1, and 4.1.1.
Who can exploit the vulnerability identified as CVE-1999-1123?
Any local user with access to the affected SunOS systems can exploit CVE-1999-1123 to gain elevated privileges.
What are the potential consequences of CVE-1999-1123 exploitation?
Exploitation of CVE-1999-1123 can lead to unauthorized access and control over the system, compromising sensitive data and resources.