Junglewise Threat Intelligence

CVE-1999-1396: Sun Microsystems SunOS privilege escalation in integer multiplication emulation

CVE-1999-1396 · Severity: high · CVSS 7.2 · Published 1992-07-21

Vendors: Sun Microsystems.

Executive brief

A vulnerability in the SunOS operating system on SPARC-based computers could allow a local user to take complete control of the system. By exploiting a flaw in how the system handles certain mathematical calculations, an attacker can gain administrative (root) privileges or cause the system to crash. This affects older versions of SunOS and could lead to unauthorized data access or service disruption.

Technical details

This vulnerability exists in the kernel-level integer multiplication emulation code for SPARC-based systems running SunOS 4.1, 4.1.1, and 4.1.2. The flaw is triggered during the emulation of multiplication instructions, which can be leveraged by a local attacker to bypass security restrictions. Successful exploitation allows a non-privileged user to escalate their privileges to root or crash the operating system (Denial of Service). The attack requires local shell access but no special user interaction. Patches were historically released by Sun Microsystems to address this issue in the early 1990s.

Affected products

  • Sun Microsystems SunOS 4.1 through 4.1.2

Timeline

  • 1992-07-21: advisory: Initial NVD publication date
  • 1992-12-31: advisory: CERT advisory CA-1992-15 published

References