Junglewise Threat Intelligence

CVE-1999-1142: Sun Microsystems SunOS privilege escalation via LD_* environment variables

CVE-1999-1142 · Severity: high · CVSS 7.2 · Published 1992-05-27

Technologies: Sunos. Vendors: Sun Microsystems, Sun.

Executive brief

A vulnerability in older versions of the SunOS operating system allows local users to gain administrative control of the system. By manipulating specific system settings used by common programs like login and mail services, an attacker can bypass security restrictions to execute commands with elevated privileges. This could lead to a complete compromise of the affected machine and unauthorized access to all stored data.

Technical details

This vulnerability is a privilege escalation flaw involving the dynamic linker and environment variable handling in SunOS 4.1.2 and earlier. Local attackers can exploit this by setting 'LD_*' environment variables (such as LD_LIBRARY_PATH or LD_PRELOAD) when executing certain dynamically linked setuid or setgid binaries, including 'login', 'su', and 'sendmail'. The issue occurs specifically in programs that change their real and effective user IDs to the same user, failing to properly sanitize the environment before execution. Successful exploitation allows a non-privileged local user to execute arbitrary code with the privileges of the setuid/setgid program, typically resulting in root access. Patch information was originally released in Sun Security Bulletin #116 and CERT Advisory CA-1992-11.

Affected products

  • Sun Microsystems SunOS 4.1.2 and earlier

Timeline

  • 1992-05-27: advisory: NVD published date
  • 1992-12-31: advisory: CERT advisory CA-1992-11 published

References

Related threats