Junglewise Threat Intelligence

CVE-1999-0033: Sun Microsystems SunOS buffer overflow in at program

CVE-1999-0033 · Severity: high · CVSS 7.2 · Published 1997-06-12

Vendors: Sun Microsystems.

Executive brief

A security vulnerability in the 'at' utility on Sun Microsystems computers allows a local user to gain unauthorized control over the system. The 'at' program is a standard tool used to schedule tasks for later execution. By exploiting this flaw, an attacker who already has basic access to the machine can escalate their privileges to perform any action, potentially leading to a full system takeover and data loss.

Technical details

A classic buffer overflow vulnerability exists in the 'at' executable on Sun systems. The flaw is triggered when the program handles specially crafted input or environment variables, leading to memory corruption. Because 'at' often runs with elevated privileges (SetUID root) to manage task scheduling for various users, a local attacker can exploit this overflow to execute arbitrary code with root-level permissions. This is a local attack requiring prior access to a shell on the target system. No network-based vector is associated with this specific vulnerability.

Affected products

  • Sun Microsystems Solaris / SunOS

Timeline

  • 1997-06-12: disclosed: Initial publication date in NVD

References