Junglewise Threat Intelligence

CVE-1999-1122: Sun Microsystems SunOS privilege escalation in restore utility

CVE-1999-1122 · Severity: medium · CVSS 4.6 · Published 1989-07-26

Vendors: Sun Microsystems.

Executive brief

A vulnerability in the 'restore' utility of SunOS allows local users to gain unauthorized administrative privileges. The 'restore' tool is used to recover files from backup media; an exploit could allow a standard user to take full control of the operating system. This could lead to the theft of sensitive data or a complete system compromise.

Technical details

A vulnerability exists in the 'restore' command in SunOS versions 4.0.3 and earlier. The 'restore' utility, which is typically used for file system recovery, contains a flaw that allows a local attacker with standard user access to execute commands or manipulate files with higher privileges. This is likely due to improper handling of setuid permissions or environment variables during execution. An attacker can exploit this to gain root access on the local system. Patches were historically issued by Sun Microsystems to address this issue.

Affected products

  • Sun Microsystems SunOS 4.0.3 and earlier

Timeline

  • 1989-07-26: advisory: NVD published date
  • 1989-07-26: disclosed: Initial disclosure via CERT CA-1989-02

References