CVE-1999-1396: High severity Sun SunOS vulnerability
Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Isolate systems running SunOS 4.1 through 4.1.2 from untrusted networks and restrict both local and remote login access to those hosts to trusted administrators only until a vendor patch or upgrade is available.
- Compensating control
Remove or disable non-essential local user accounts and restrict interactive shells/privileges for remaining accounts (apply principle of least privilege) on SunOS 4.1 through 4.1.2 to reduce risk of local exploitation.
- Operational
Assume possible local compromise: audit system logs and binaries for signs of privilege escalation or tampering, verify integrity of critical system files, rotate any credentials or keys that may have been exposed, and reinstall or restore from known-good media if compromise is detected.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1396?
CVE-1999-1396 has a high severity level as it allows local users to gain root access or crash the system.
How do I fix CVE-1999-1396?
To fix CVE-1999-1396, upgrade to a patched version of SunOS that addresses this vulnerability.
Who is affected by CVE-1999-1396?
CVE-1999-1396 affects local users on systems running SunOS versions 4.1, 4.1.1, and 4.1.2.
What type of vulnerability is CVE-1999-1396?
CVE-1999-1396 is a local privilege escalation vulnerability related to integer multiplication emulation.
What is the impact of exploiting CVE-1999-1396?
Exploiting CVE-1999-1396 can result in unauthorized root access or a denial-of-service condition on the affected system.