CVE Vulnerabilities

CVE-1999-1432

Published: Jul 16, 1998 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.

Affected Software

Name Vendor Start Version End Version
Solaris Sun 2.4 (including) 2.4 (including)
Solaris Sun 2.5 (including) 2.5 (including)
Solaris Sun 2.5.1 (including) 2.5.1 (including)
Solaris Sun 2.6 (including) 2.6 (including)
Sunos Sun - (including) - (including)
Sunos Sun 5.4 (including) 5.4 (including)
Sunos Sun 5.5 (including) 5.5 (including)
Sunos Sun 5.5.1 (including) 5.5.1 (including)

References