CVE-1999-1438: High severity Sun SunOS vulnerability

Published Feb 22, 1991
·
Updated

Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.

Affected Software

3 affected components
Sun SunOS=4.0.3
Sun SunOS=4.1
Sun SunOS<=4.1.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove SunOS /bin/mail from your environment.

    If mail functionality provided by /bin/mail is not required on the system, uninstall or remove the /bin/mail binary to eliminate the vulnerable component.

  2. Configuration

    Remove the setuid bit (if present) and change file permissions on /bin/mail so that only root can execute it (e.g., chmod 700 /bin/mail or equivalent).

    SunOS /bin/mail file permissions = remove setuid; restrict execute to root
  3. Compensating control

    Prevent unprivileged local users from executing the vulnerable binary by restricting shell/login access and using host-based access controls (local ACLs, sudoers restrictions, or similar) to limit which accounts can run /bin/mail; isolate or limit access to affected hosts to trusted administrators until a vendor patch is available.

Event History

Feb 22, 1991
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1438?

CVE-1999-1438 is considered to be a critical vulnerability due to its potential to allow local users to gain root privileges.

2

How do I fix CVE-1999-1438?

To mitigate CVE-1999-1438, upgrade to a patched version of SunOS that addresses this vulnerability.

3

Which versions of SunOS are affected by CVE-1999-1438?

CVE-1999-1438 affects SunOS versions 4.1.1 and earlier, including 4.0.3.

4

Is CVE-1999-1438 a local or remote exploitation vulnerability?

CVE-1999-1438 is a local exploitation vulnerability, meaning it requires local access to the system to be exploited.

5

Can CVE-1999-1438 be exploited by non-privileged users?

Yes, CVE-1999-1438 can be exploited by non-privileged local users to gain root privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203