First published: Fri Dec 31 1999(Updated: )
The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.0 | |
SunOS | =5.0 | |
=5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1585 is considered a critical vulnerability due to the potential for local attackers with physical access to gain root privileges.
To fix CVE-1999-1585, ensure to upgrade to a patched version of Sun Solaris that addresses this issue.
The affected programs are rcS and mountall in Sun Solaris 2.x, particularly versions before 2.4.
CVE-1999-1585 requires physical access to the machine to exploit, making it a local privilege escalation vulnerability.
Systems running Sun Solaris 2.x, before version 2.4, are vulnerable to CVE-1999-1585.