First published: Mon Nov 10 1997(Updated: )
Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Solstice Adminsuite | =2.1 | |
Sun Solstice Adminsuite | =2.2 | |
Sun Solstice Adminsuite | =2.1 | |
Sun Solstice Adminsuite | =2.2 | |
=2.1 | ||
=2.1 | ||
=2.2 | ||
=2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1426 has a medium severity level due to its potential for local users to overwrite arbitrary files.
To fix CVE-1999-1426, ensure that symbolic link handling is secure during NIS database updates.
CVE-1999-1426 affects users of Solaris Solstice AdminSuite versions 2.1 and 2.2.
CVE-1999-1426 is a symbolic link vulnerability that allows local privilege escalation.
No, CVE-1999-1426 can only be exploited by local users on the same system.