The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.
References
Link | Resource |
---|---|
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/122&type=0&nav=sec.sba | Patch Vendor Advisory |
http://www.ciac.org/ciac/bulletins/e-01.shtml | Patch Vendor Advisory |
http://www.osvdb.org/6436 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/549 | |
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/122&type=0&nav=sec.sba | Patch Vendor Advisory |
http://www.ciac.org/ciac/bulletins/e-01.shtml | Patch Vendor Advisory |
http://www.osvdb.org/6436 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/549 |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/122&type=0&nav=sec.sba - Patch, Vendor Advisory | |
References | () http://www.ciac.org/ciac/bulletins/e-01.shtml - Patch, Vendor Advisory | |
References | () http://www.osvdb.org/6436 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/549 - |
Information
Published : 1993-10-01 04:00
Updated : 2024-11-20 23:30
NVD link : CVE-1999-1137
Mitre link : CVE-1999-1137
CVE.ORG link : CVE-1999-1137
JSON object : View
Products Affected
sun
- sunos
- solaris
CWE