Executive brief
A security flaw in older Sun Microsystems operating systems allows any user with local access to the computer to access the microphone. This could allow an unauthorized person to listen to or record private conversations occurring near the physical machine. This poses a significant privacy risk for workstations located in sensitive environments.
Technical details
The vulnerability is caused by improper file system permissions on the /dev/audio device node. In affected versions of Solaris and SunOS, the device is world-readable by default. A local attacker with shell access can exploit this by reading directly from the device file to capture raw audio input. This allows for the unauthorized monitoring of environmental audio if a microphone is connected to the system. The issue is resolved by restricting device permissions to the console user or authorized groups.
Affected products
- Sun Microsystems Solaris 2.2 and earlier
- Sun Microsystems SunOS 4.1.x
Timeline
- 1993-10-01: disclosed: Initial publication date