Junglewise Threat Intelligence

CVE-1999-1192: Sun Solaris buffer overflow in eeprom utility

CVE-1999-1192 · Severity: high · CVSS 7.2 · Published 1997-06-24

Vendors: Sun Microsystems.

Executive brief

A security vulnerability exists in the eeprom utility of older Solaris operating systems, which is used to display or modify firmware configuration parameters. A local user with basic access to the system can exploit this flaw to gain full administrative (root) control. This could lead to a complete compromise of the server, including unauthorized data access and system manipulation.

Technical details

A classic stack-based buffer overflow exists in the 'eeprom' executable in SunOS/Solaris. The vulnerability is triggered when the program processes an excessively long command line argument without proper bounds checking. Because the eeprom utility often requires elevated privileges to interact with system hardware, an attacker can exploit this overflow to overwrite the instruction pointer and execute arbitrary code with root privileges. This is a local exploit requiring shell access to the target machine. Patches were historically released by Sun Microsystems to address this issue.

Affected products

  • Sun Microsystems Solaris 2.5.1 and earlier
  • Sun Microsystems SunOS 5.5.1 and earlier

Timeline

  • 1997-06-24: disclosed: Initial publication date
  • 1997-06-24: advisory: NVD publication date

References