CVE-1999-1137: Low severity Sun Solaris vulnerability

Published Oct 1, 1993
·
Updated

The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.

Affected Software

5 affected components
Sun Solaris
Sun Sunos=4.1
Sun Sunos=5.0
Sun Sunos
Sun Sunos<=5.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Change the file permissions on /dev/audio to prevent non-privileged local users from reading the device (restrict read access to root or to a dedicated, trusted group).

    Solaris and SunOS /dev/audio device device node permissions = remove read access for non-privileged local users

Event History

Oct 1, 1993
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1137?

CVE-1999-1137 is considered a moderate severity vulnerability due to the potential for local users to monitor audio via the /dev/audio device.

2

How do I fix CVE-1999-1137?

To fix CVE-1999-1137, it is recommended to change the permissions on the /dev/audio device to restrict access.

3

Who is affected by CVE-1999-1137?

CVE-1999-1137 affects local users on Solaris 2.2 and earlier, as well as SunOS 4.1.x systems.

4

What can an attacker do with CVE-1999-1137?

An attacker exploiting CVE-1999-1137 can potentially eavesdrop on conversations by accessing the /dev/audio device.

5

Is CVE-1999-1137 a remote exploit?

No, CVE-1999-1137 is a local exploit, meaning it requires access to the affected system to be exploited.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203