CVE-1999-1587: Low severity Sun SunOS vulnerability

Published Dec 31, 1999
·
Updated

/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.

Affected Software

2 affected components
Sun SunOS=5.8
Sun Solaris=9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove /usr/ucb/ps from your environment.

    If /usr/ucb/ps is not required, remove or uninstall the /usr/ucb/ps binary to eliminate the ability for local users to view environment variables of arbitrary processes via the -e option.

  2. Configuration

    Restrict access to /usr/ucb/ps so that non-privileged local users cannot execute it (for example, change ownership to root and remove world/other execute permissions or set mode to 0700). This prevents use of the -e option to view arbitrary process environment variables.

    /usr/ucb/ps file permissions / access = restrict execution to privileged users (e.g., root)

Event History

Dec 31, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Mar 29, 2006
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1587?

CVE-1999-1587 is considered a moderate severity vulnerability due to the exposure of sensitive environment variable information.

2

How do I fix CVE-1999-1587?

To fix CVE-1999-1587, restrict the use of the /usr/ucb/ps command by modifying user permissions or disabling the -e option.

3

Who is affected by CVE-1999-1587?

CVE-1999-1587 affects local users on Sun Microsystems Solaris 8 and 9 systems, as well as certain earlier releases.

4

What is the impact of CVE-1999-1587?

The impact of CVE-1999-1587 allows local users to view the environment variables of arbitrary processes, potentially exposing sensitive information.

5

Is there a workaround for CVE-1999-1587?

A workaround for CVE-1999-1587 includes restricting access to the /usr/ucb/ps command to trusted users only.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203