Junglewise Threat Intelligence

CVE-1999-0099: Sun Solaris syslog buffer overflow

CVE-1999-0099 · Severity: critical · CVSS 10 · Published 1995-10-19

Vendors: Sun Microsystems.

Executive brief

A critical security flaw exists in the syslog utility, a standard component used by operating systems to record system logs and error messages. An attacker can exploit this vulnerability to take complete control of the affected system with the highest possible privileges (root). This could lead to total data theft, system destruction, or the use of the compromised machine to launch further attacks.

Technical details

A buffer overflow vulnerability exists in the syslog utility, a core system logging service. The flaw is caused by improper bounds checking when processing log messages, allowing an attacker to overwrite memory and execute arbitrary code. This vulnerability can be exploited either locally or remotely without authentication. Successful exploitation grants the attacker root-level access, providing full administrative control over the host operating system. Historical data indicates this affected Sun Microsystems Solaris and SunOS environments.

Affected products

  • Sun Microsystems Solaris 2.3, 2.4
  • Sun Microsystems SunOS 5.3, 5.4

Timeline

  • 1995-10-19: disclosed: Initial publication date

References