Junglewise Threat Intelligence

CVE-1999-1158: Sun Solaris buffer overflow in PAM and unix_scheme

CVE-1999-1158 · Severity: high · CVSS 7.2 · Published 1997-05-13

Vendors: Sun Microsystems.

Executive brief

A security vulnerability exists in the authentication components of older Sun Solaris operating systems. This flaw allows a person who already has a standard user account on the system to gain full administrative (root) control. By exploiting this issue through common password-changing tools, an attacker could access any file, modify system settings, or disrupt operations.

Technical details

A buffer overflow vulnerability exists in the Pluggable Authentication Module (PAM) in Solaris 2.5 and 2.5.1, and in the unix_scheme component in Solaris 2.3 and 2.4. The flaw is triggered when processing input through setuid programs that utilize these authentication modules, such as passwd, yppasswd, and nispasswd. A local, unprivileged attacker can exploit this by providing specially crafted input to these utilities to overwrite memory and execute arbitrary code with elevated privileges. Successful exploitation results in a full compromise of the host (root access). Sun Microsystems released patches for these versions under Security Bulletin #139.

Affected products

  • Sun Microsystems Solaris 2.3, 2.4, 2.5, 2.5.1

Timeline

  • 1997-05-13: disclosed
  • 1997-05-13: advisory

References