Junglewise Threat Intelligence

CVE-1999-1428: Sun Solaris Solstice AdminSuite privilege escalation in Database Manager

CVE-1999-1428 · Severity: medium · CVSS 6.2 · Published 1997-11-10

Vendors: Sun Microsystems.

Executive brief

Sun Microsystems Solstice AdminSuite, a tool used for managing system databases on Solaris, contains a security flaw that allows local users to gain elevated system privileges. By misusing the 'save' feature within the Database Manager, an attacker who already has access to the system can perform actions with the authority of the 'bin' group. This could lead to unauthorized access to sensitive system files or the ability to modify critical system configurations.

Technical details

A privilege escalation vulnerability exists in the Database Manager component of Sun Microsystems Solstice AdminSuite versions 2.1 and 2.2. The Database Manager process runs with setgid 'bin' privileges, and the 'save' functionality fails to properly restrict file operations or drop privileges during file writes. A local attacker can exploit this behavior to overwrite or create files with 'bin' group ownership, potentially leading to full system compromise. The vulnerability is triggered through the graphical interface's save option. Patch information was originally detailed in Sun Security Bulletin #145.

Affected products

  • Sun Microsystems Solstice AdminSuite 2.1, 2.2

Timeline

  • 1997-11-10: disclosed: Initial publication date

References