CVE-1999-1297: Low severity Sun SunOS vulnerability

Published Jul 15, 1998
·
Updated

cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.

Affected Software

6 affected components
Sun SunOS=4.1.4
Sun SunOS=4.1
Sun SunOS=4.1.1
Sun SunOS=4.1.3
Sun SunOS=4.1.2
Sun SunOS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove cmdtool (OpenWindows/XView) from your environment.

    Uninstall or remove cmdtool (part of OpenWindows/XView) from affected SunOS systems if the component is not required.

  2. Configuration

    Disable or remap the L2/AGAIN key in cmdtool/OpenWindows/XView so it cannot be used to display unechoed characters (preventing disclosure of password input).

    cmdtool (OpenWindows/XView) L2/AGAIN key = disabled
  3. Compensating control

    Restrict and secure physical access to affected systems (limit console access, lock server rooms, and control who can interact with the machine) to mitigate attacks that require physical presence.

Event History

Jul 15, 1998
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1297?

CVE-1999-1297 is considered to have a moderate severity, as it allows attackers with physical access to potentially compromise the security of the system.

2

How do I fix CVE-1999-1297?

To fix CVE-1999-1297, ensure that physical access to the system is restricted and apply any security patches provided by the vendor for affected versions of SunOS.

3

What versions of SunOS are affected by CVE-1999-1297?

CVE-1999-1297 affects SunOS versions 4.1, 4.1.1, 4.1.2, 4.1.3, and 4.1.4.

4

What does CVE-1999-1297 exploit?

CVE-1999-1297 exploits the cmdtool in OpenWindows and XView, allowing attackers to display unechoed characters, including passwords.

5

Who is at risk from CVE-1999-1297?

Users with physical access to systems running affected versions of SunOS are at risk from CVE-1999-1297.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203