CVE-1999-1297: Low severity Sun SunOS vulnerability
cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
cmdtool (OpenWindows/XView)from your environment.Uninstall or remove cmdtool (part of OpenWindows/XView) from affected SunOS systems if the component is not required.
- Configuration
Disable or remap the L2/AGAIN key in cmdtool/OpenWindows/XView so it cannot be used to display unechoed characters (preventing disclosure of password input).
cmdtool (OpenWindows/XView) L2/AGAIN key = disabled - Compensating control
Restrict and secure physical access to affected systems (limit console access, lock server rooms, and control who can interact with the machine) to mitigate attacks that require physical presence.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1297?
CVE-1999-1297 is considered to have a moderate severity, as it allows attackers with physical access to potentially compromise the security of the system.
How do I fix CVE-1999-1297?
To fix CVE-1999-1297, ensure that physical access to the system is restricted and apply any security patches provided by the vendor for affected versions of SunOS.
What versions of SunOS are affected by CVE-1999-1297?
CVE-1999-1297 affects SunOS versions 4.1, 4.1.1, 4.1.2, 4.1.3, and 4.1.4.
What does CVE-1999-1297 exploit?
CVE-1999-1297 exploits the cmdtool in OpenWindows and XView, allowing attackers to display unechoed characters, including passwords.
Who is at risk from CVE-1999-1297?
Users with physical access to systems running affected versions of SunOS are at risk from CVE-1999-1297.