CVE-1999-1142: High severity Sun SunOS vulnerability

Published May 27, 1992
·
Updated

SunOS 4.1.2 and earlier allows local users to gain privileges via "LD" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.

Affected Software

1 affected component
Sun SunOS<=4.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure LD_* environment variables are cleared or ignored before executing dynamically linked setuid/setgid programs (for example login, su, sendmail). Modify wrappers, startup scripts, or the process invocation environment to unset all LD_* variables prior to running these programs.

    login, su, sendmail LD_* environment handling = unset / ignored for setuid/setgid executables
  2. Configuration

    Replace dynamically linked setuid/setgid versions of login, su, and sendmail with statically linked equivalents so the dynamic linker (and LD_* environment variables) cannot be used to gain elevated privileges.

    login, su, sendmail binaries linkage = statically linked

Event History

May 27, 1992
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1142?

CVE-1999-1142 is considered a high-severity vulnerability due to its potential for privilege escalation.

2

How do I fix CVE-1999-1142?

To fix CVE-1999-1142, upgrade SunOS to a version later than 4.1.2 which does not allow LD_* environmental variable exploitation.

3

Who is affected by CVE-1999-1142?

Local users on SunOS versions 4.1.2 and earlier can be affected by CVE-1999-1142.

4

What systems are vulnerable to CVE-1999-1142?

SunOS operating systems up to version 4.1.2 are vulnerable to CVE-1999-1142.

5

What are the implications of CVE-1999-1142?

The implications of CVE-1999-1142 include unauthorized privilege escalation, allowing local users to gain access to restricted functionalities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203