First published: Tue May 13 1997(Updated: )
Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.3 | |
Sun SunOS | =5.5 | |
Sun SunOS | =5.4 | |
Sun SunOS | =5.5.1 | |
=5.3 | ||
=5.4 | ||
=5.5 | ||
=5.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1158 is considered a critical vulnerability as it allows local users to gain root privileges on affected Solaris systems.
To fix CVE-1999-1158, apply the appropriate patches provided by Sun Microsystems for your version of Solaris.
CVE-1999-1158 affects Solaris 2.3, 2.4, 2.5, 2.5.1, and 2.5.1 systems.
Programs such as passwd, yppasswd, and nispasswd are vulnerable due to CVE-1999-1158.
No, CVE-1999-1158 is a local vulnerability, meaning only local users can exploit it.