CVE-1999-1432: High severity Sun Solaris vulnerability
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the power-management subsystem or session suspend/resume scripts to start the xlock process (or otherwise lock the console) before initiating sys-suspend so the console is already locked when the system begins and during restore.
Solaris power management (Powermanagement) start xlock before sys-suspend = enabled - Configuration
Enable immediate authentication on resume from suspend (require password/login immediately upon wake) so any keyboard input during restore is rejected until the user authenticates.
Solaris session/screen lock require authentication on resume = enabled - Compensating control
Restrict physical access to affected systems (secure consoles, lock server rooms, limit physical console access) until a configuration fix is applied to prevent unauthorized users from entering input during suspend/resume.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1432?
CVE-1999-1432 is considered a moderate severity vulnerability due to the potential for unauthorized access during the system's restore process.
How do I fix CVE-1999-1432?
To fix CVE-1999-1432, ensure that the xlock process is properly configured to engage before any input can be entered after sys-suspend is initiated.
Who is affected by CVE-1999-1432?
CVE-1999-1432 affects users of Solaris versions 2.4 through 2.6, as well as SunOS 5.4 and 5.5.
What is the attack vector for CVE-1999-1432?
The attack vector for CVE-1999-1432 involves physical access to the machine, allowing an attacker to input characters during a brief window after system restoration.
Can CVE-1999-1432 be exploited remotely?
CVE-1999-1432 cannot be exploited remotely as it requires physical access to the affected machine.