CVE-1999-1191: Buffer Overflow
Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Oracle Solaris chkeyfrom your environment.Uninstall or remove the chkey utility if it is not required on affected systems.
- Configuration
Remove the setuid bit from the chkey binary so it cannot be used to escalate privileges (for example: remove or clear the SUID permission on the chkey executable).
chkey (Solaris) setuid = disabled - Compensating control
Restrict local access to systems with the vulnerable chkey (limit or remove untrusted local accounts, tighten host-based access controls) until an official vendor patch or fixed version is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1191?
CVE-1999-1191 is classified as a critical vulnerability due to its ability to allow local users to gain root privileges.
How do I fix CVE-1999-1191?
To fix CVE-1999-1191, apply the latest patches provided by Sun Microsystems for Solaris 2.5.1 and earlier.
What are the affected versions for CVE-1999-1191?
CVE-1999-1191 affects Solaris versions 2.4, 2.5, and 2.5.1 as well as SunOS versions 5.4 and 5.5.
Who is impacted by CVE-1999-1191?
Local users with access to the affected Solaris and SunOS systems can exploit CVE-1999-1191 to gain unauthorized root access.
What kind of vulnerability is CVE-1999-1191?
CVE-1999-1191 is a buffer overflow vulnerability that can be exploited via long command line arguments.