Vulnerability Name: | CVE-1999-1587 (CCN-25460) | ||||||||
Assigned: | 1999-12-31 | ||||||||
Published: | 1999-12-31 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-1999-1587 Source: CCN Type: SA19426 Sun Solaris Process Environment Disclosure Security Issue Source: SECUNIA Type: Patch, Vendor Advisory 19426 Source: CCN Type: SECTRACK ID: 1015833 Sun Solaris `/usr/ucb/ps` May Disclose Sensitive Information to Local Users Source: SECTRACK Type: Patch 1015833 Source: CCN Type: Sun Alert ID: 102215 Security Vulnerability With The "/usr/ucb/ps" Command Source: SUNALERT Type: Exploit, Patch 102215 Source: OSVDB Type: UNKNOWN 24200 Source: CCN Type: OSVDB ID: 24200 Solaris /usr/ucb/ps Process Environment Variable Disclosure Source: CCN Type: OSVDB ID: 33113 HP Tru64 /usr/ucb/ps Arbitrary Process Environment Disclosure Source: BID Type: UNKNOWN 19662 Source: CCN Type: BID-19662 Sun Solaris UCB/PS Command Local Information Disclosure Vulnerability Source: MISC Type: Exploit http://www.sunmanagers.org/archives/1996/1383.html Source: VUPEN Type: UNKNOWN ADV-2006-1123 Source: XF Type: UNKNOWN solaris-ps-information-disclosure(25460) Source: XF Type: UNKNOWN solaris-ps-information-disclosure(25460) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1470 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |