Search

published date: September 17, 1993

CVE-1999-1318 : /usr/5bin/su in SunOS 4.1.3...

Description

/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.

Product(s):

  • Sun SunOS
  • Sun SunOS (formerly Solaris)
  • Sun SunOS 3.5
  • Sun SunOS 4.0.1
  • Sun SunOS 4.0.2
  • Sun SunOS 4.0.3

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-1999-1318, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-1999-1318 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?