7.5
CVSSv2

CVE-1999-1432

Published: 16/07/1998 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Power management (Powermanagement) on Solaris 2.4 up to and including 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

sun sunos 5.4

sun solaris 2.4

sun sunos -

sun sunos 5.5

sun sunos 5.5.1

sun solaris 2.5

sun solaris 2.6

sun solaris 2.5.1

Exploits

source: wwwsecurityfocuscom/bid/160/info A vulnerability exists in Sun's power management software under Solaris versions 24-26 (although only 26 as part of the main distribution) The sys-suspend program is initiated when a user runs the program, or presses the power key on a sun keyboard This program moves the contents of memory to ...