Junglewise Threat Intelligence

CVE-1999-0151: SATAN session key disclosure via web browser navigation

CVE-1999-0151 · Severity: high · CVSS 7.6 · Published 1995-04-03

Executive brief

A vulnerability in the SATAN network security tool could allow an attacker to gain full administrative (root) control over a system. This occurs when a user running the tool visits other websites while the tool is active, which can leak sensitive session keys. If exploited, an attacker could take over the security scanning session and compromise the host machine.

Technical details

The SATAN (Security Administrator Tool for Analyzing Networks) utility is vulnerable to session key disclosure via the web browser interface. When a user navigates to an external website while a SATAN session is active, the session key may be leaked (likely via the HTTP Referer header or browser history). An attacker who obtains this key can hijack the session, potentially leading to unauthorized command execution with root privileges on the host running the tool. This vulnerability requires the user to interact with an external site while the tool is running.

Affected products

  • Wietse Venema and Dan Farmer SATAN (Security Administrator Tool for Analyzing Networks)

Timeline

  • 1995-04-03: disclosed

References