First published: Sat May 17 1997(Updated: )
The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =3.1 | |
FreeBSD Kernel | =2.2.5 | |
Oracle Solaris and Zettabyte File System (ZFS) | =2.5.1 | |
Oracle Solaris and Zettabyte File System (ZFS) | =2.5.1 | |
Oracle Solaris and Zettabyte File System (ZFS) | =2.5 | |
FreeBSD Kernel | =2.2.2 | |
FreeBSD Kernel | =2.2.3 | |
Sun SunOS | =5.5 | |
FreeBSD Kernel | =2.2.8 | |
FreeBSD Kernel | =3.0 | |
FreeBSD Kernel | =2.2.4 | |
FreeBSD Kernel | =2.2.6 | |
Sun SunOS | =5.5.1 | |
Sun SunOS | =5.0 | |
Sun SunOS | =4.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =2.6 | |
Sun SunOS | ||
SunOS | ||
SunOS | =4.0 | |
SunOS | =5.0 | |
SunOS | =5.5 | |
SunOS | =5.5.1 | |
=2.2.2 | ||
=2.2.3 | ||
=2.2.4 | ||
=2.2.5 | ||
=2.2.6 | ||
=2.2.8 | ||
=3.0 | ||
=3.1 | ||
=2.5 | ||
=2.5.1 | ||
=2.5.1 | ||
=2.6 | ||
=4.0 | ||
=5.0 | ||
=5.5 | ||
=5.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1402 is considered a local privilege escalation vulnerability that could potentially disrupt operations.
To fix CVE-1999-1402, adjust the access permissions for the UNIX domain sockets or upgrade to a patched version of the affected software.
CVE-1999-1402 affects Solaris 2.x, SunOS 4.x, and various BSD-based operating systems before 4.4.
The impact of CVE-1999-1402 is that local users can connect to unsecured UNIX domain sockets and potentially control or disrupt the application using them.
No, CVE-1999-1402 requires local access to the system for exploitation.