Junglewise Threat Intelligence

CVE-1999-1425: Sun Microsystems Solaris Solstice AdminSuite privilege escalation via NIS maps

CVE-1999-1425 · Severity: medium · CVSS 6.2 · Published 1997-11-10

Vendors: Sun Microsystems.

Executive brief

Sun Microsystems Solstice AdminSuite, a tool used for managing Solaris system environments, contains a security flaw in how it handles file permissions. This vulnerability allows a local user on the system to gain full administrative control by modifying sensitive system files. This could lead to unauthorized access to all data on the server and a complete compromise of the operating system.

Technical details

A vulnerability exists in Sun Microsystems Solstice AdminSuite 2.1 due to improper permission assignment on source files used for Network Information Service (NIS) maps. Specifically, the application sets insecure write permissions on critical files, including those that feed into the /etc/passwd map. A local attacker with low privileges can exploit this by modifying these source files to inject unauthorized accounts or change existing credentials. This results in a local privilege escalation to root. The vulnerability is mitigated by the requirement for local access and the specific configuration of NIS map source files. Patches were historically provided by Sun Microsystems in security bulletin 145.

Affected products

  • Sun Microsystems Solstice AdminSuite 2.1

Timeline

  • 1997-11-10: disclosed: Initial publication date
  • 1997-11-10: advisory: NVD publication date

References