CVE-1999-1426: Medium severity Sun Solstice Adminsuite vulnerability
Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sun Solstice Adminsuitefrom your environment.Uninstall or disable Sun Solstice AdminSuite (AdminSuite) 2.1 until a vendor-supplied patch/fix is available.
- Compensating control
Prevent unprivileged local users from invoking AdminSuite NIS database update functionality: restrict execution to trusted administrative accounts, remove execute permissions for non-admin users, and ensure only administrators perform NIS database updates. Additionally, limit local account capabilities to create or follow symlinks in directories used during NIS updates until the vulnerability is remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1426?
CVE-1999-1426 has a medium severity level due to its potential for local users to overwrite arbitrary files.
How do I fix CVE-1999-1426?
To fix CVE-1999-1426, ensure that symbolic link handling is secure during NIS database updates.
Who is affected by CVE-1999-1426?
CVE-1999-1426 affects users of Solaris Solstice AdminSuite versions 2.1 and 2.2.
What type of vulnerability is CVE-1999-1426?
CVE-1999-1426 is a symbolic link vulnerability that allows local privilege escalation.
Can CVE-1999-1426 be exploited remotely?
No, CVE-1999-1426 can only be exploited by local users on the same system.