First published: Wed Jul 15 1998(Updated: )
cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =4.1.4 | |
Sun SunOS | =4.1 | |
Sun SunOS | =4.1.1 | |
Sun SunOS | =4.1.3 | |
Sun SunOS | =4.1.2 | |
Sun SunOS | ||
=4.1 | ||
=4.1.1 | ||
=4.1.2 | ||
=4.1.3 | ||
=4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1297 is considered to have a moderate severity, as it allows attackers with physical access to potentially compromise the security of the system.
To fix CVE-1999-1297, ensure that physical access to the system is restricted and apply any security patches provided by the vendor for affected versions of SunOS.
CVE-1999-1297 affects SunOS versions 4.1, 4.1.1, 4.1.2, 4.1.3, and 4.1.4.
CVE-1999-1297 exploits the cmdtool in OpenWindows and XView, allowing attackers to display unechoed characters, including passwords.
Users with physical access to systems running affected versions of SunOS are at risk from CVE-1999-1297.