CVE-1999-1427: Medium severity Sun Solstice Adminsuite vulnerability
Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sun Solstice AdminSuitefrom your environment.Uninstall or remove Sun Solstice AdminSuite (AdminSuite) versions 2.1 and 2.2 from affected systems until a vendor-supplied fix is available.
- Compensating control
Restrict local user access to systems running AdminSuite (limit interactive logins and unprivileged accounts). Protect AdminSuite installation directories and lockfile locations with strict filesystem permissions/ACLs and isolate affected systems from untrusted users until a patch is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1427?
CVE-1999-1427 is considered a critical vulnerability due to the potential for local users to gain root privileges.
How do I fix CVE-1999-1427?
To fix CVE-1999-1427, ensure that file creation permissions are securely set and update to a patched version of the software.
Who is affected by CVE-1999-1427?
CVE-1999-1427 affects users of Solaris Solstice AdminSuite versions 2.1 and 2.2.
Can CVE-1999-1427 be exploited remotely?
CVE-1999-1427 cannot be exploited remotely as it requires local access to the system.
What systems are at risk from CVE-1999-1427?
Systems running Solaris Solstice AdminSuite 2.1 and 2.2 are at risk from CVE-1999-1427.