CVE-1999-1396: High severity Sun SunOS vulnerability

Published Jul 21, 1992
·
Updated

Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).

Affected Software

3 affected components
Sun SunOS=4.1
Sun SunOS=4.1.1
Sun SunOS=4.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Isolate systems running SunOS 4.1 through 4.1.2 from untrusted networks and restrict both local and remote login access to those hosts to trusted administrators only until a vendor patch or upgrade is available.

  2. Compensating control

    Remove or disable non-essential local user accounts and restrict interactive shells/privileges for remaining accounts (apply principle of least privilege) on SunOS 4.1 through 4.1.2 to reduce risk of local exploitation.

  3. Operational

    Assume possible local compromise: audit system logs and binaries for signs of privilege escalation or tampering, verify integrity of critical system files, rotate any credentials or keys that may have been exposed, and reinstall or restore from known-good media if compromise is detected.

Event History

Jul 21, 1992
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1396?

CVE-1999-1396 has a high severity level as it allows local users to gain root access or crash the system.

2

How do I fix CVE-1999-1396?

To fix CVE-1999-1396, upgrade to a patched version of SunOS that addresses this vulnerability.

3

Who is affected by CVE-1999-1396?

CVE-1999-1396 affects local users on systems running SunOS versions 4.1, 4.1.1, and 4.1.2.

4

What type of vulnerability is CVE-1999-1396?

CVE-1999-1396 is a local privilege escalation vulnerability related to integer multiplication emulation.

5

What is the impact of exploiting CVE-1999-1396?

Exploiting CVE-1999-1396 can result in unauthorized root access or a denial-of-service condition on the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203