CVE-1999-1194: High severity digital ultrix vulnerability
chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Digital Ultrix chrootfrom your environment.If the chroot binary is not required, remove/uninstall the insecurely installed chroot from affected Digital Ultrix 4.1 and 4.0 systems to eliminate the local privilege escalation vector.
- Compensating control
Until a secure fix or replacement is available, restrict and harden local access on affected Digital Ultrix hosts: disable or remove unneeded local accounts, restrict interactive logins, and limit administrative access to trusted operators only. Monitor logs for signs of local privilege escalation.
- Operational
Investigate affected systems for evidence of local privilege escalation and related misuse; if compromise is suspected, perform incident response (containment, eradication, recovery) and rotate any potentially exposed credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1194?
CVE-1999-1194 is considered a high-severity vulnerability due to the potential for local users to gain elevated privileges.
How do I fix CVE-1999-1194?
To fix CVE-1999-1194, ensure that the chroot environment is properly configured and restrict access permissions to prevent local users from exploiting it.
Which software versions are affected by CVE-1999-1194?
CVE-1999-1194 affects Digital Ultrix versions 4.0 and 4.1.
Who is vulnerable to CVE-1999-1194?
Local users on systems running Digital Ultrix 4.0 or 4.1 are vulnerable to CVE-1999-1194.
Is CVE-1999-1194 still relevant today?
CVE-1999-1194 remains relevant for legacy systems still in use that have not been updated or replaced.