CVE-1999-1423: Low severity Sun SunOS vulnerability

Published Jun 26, 1997
·
Updated

ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.

Affected Software

9 affected components
Sun SunOS=5.3
Sun Solaris=2.4
Sun Solaris=2.5.1
Sun Solaris=2.5.1
Sun Solaris=2.5
Sun SunOS=5.5
Sun SunOS=5.4
Sun SunOS=5.5.1
Sun Solaris=2.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Restrict execution of the ping binary so that only privileged users can run it (for example, remove execute permissions or remove the setuid bit for non-privileged users) to prevent local users from invoking ping -i to multicast addresses via the loopback interface.

    ping (Solaris) execution permission = restricted to privileged users
  2. Compensating control

    Block or filter multicast traffic on the loopback interface (and/or apply local firewall rules) to prevent ping requests to multicast addresses over lo, thereby mitigating the ability of local users to trigger the crash.

  3. Operational

    Avoid running ping -i to multicast addresses via the loopback interface on affected Solaris/SunOS systems until a vendor fix is available; monitor systems for crashes and apply normal recovery procedures if a denial-of-service occurs.

Event History

Jun 26, 1997
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1423?

CVE-1999-1423 is considered a denial of service vulnerability that can cause system crashes.

2

How can CVE-1999-1423 affect systems using Solaris?

CVE-1999-1423 allows local users to crash the system by sending ping requests to a multicast address via the loopback interface.

3

Which versions of Solaris are vulnerable to CVE-1999-1423?

CVE-1999-1423 affects Solaris versions 2.3 through 2.6, including specific builds of SunOS.

4

How do I mitigate CVE-1999-1423?

To mitigate CVE-1999-1423, restrict access to the ping command or filter multicast ping requests on the loopback interface.

5

Is there a patch available for CVE-1999-1423?

There are no widely recognized patches available for CVE-1999-1423, so implementing network security best practices is crucial.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203