CVE-1999-1142 Information

Description

SunOS 4.1.2 and earlier allows local users to gain privileges via \LD_*\ environmental variables to certain dynamically linked setuid or setgid programs such as (1) login (2) su or (3) sendmail that change the real and effective user ids to the same user.

Reference

http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/116 http://www.cert.org/advisories/CA-1992-11.html https://exchange.xforce.ibmcloud.com/vulnerabilities/3152

Share on: