Junglewise Threat Intelligence

CVE-1999-1388: Sun Microsystems SunOS symlink attack in passwd utility

CVE-1999-1388 · Severity: medium · CVSS 6.2 · Published 1994-05-13

Technologies: Sunos. Vendors: Sun Microsystems, Sun.

Executive brief

A vulnerability in the password management utility of SunOS 4.1.x allows local users to overwrite critical system files. By exploiting how the system handles file links, an attacker can trick the utility into modifying files they should not have access to. This could lead to a complete system compromise or a total loss of system availability.

Technical details

The passwd utility in SunOS 4.1.x is vulnerable to a symbolic link (symlink) attack. A local attacker can exploit the '-F' command line argument to redirect file write operations to arbitrary locations on the file system. By creating a symlink at a temporary file path used by the utility, the attacker can force the elevated process to overwrite sensitive system files. This results in a loss of integrity and availability, potentially allowing for full system takeover. This is a classic race condition/link following vulnerability in a setuid or privileged binary.

Affected products

  • Sun Microsystems SunOS 4.1.x

Timeline

  • 1994-05-13: disclosed: Initial publication date in NVD/Bugtraq references.

References

Related threats