CVE-1999-1137
published 1993-10-01CVE-1999-1137: The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.36%
28.7th percentile
The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | sunos | <= 5.2 | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Sun Solaris 2.2 Audio Device /dev/audio privileges management (XFDB-549 / OSVDB-6436)
vuldb·2026-04-16·CVSS 2.1
CVE-1999-1137 [LOW] Sun Solaris 2.2 Audio Device /dev/audio privileges management (XFDB-549 / OSVDB-6436)
A vulnerability, which was classified as problematic, was found in Sun Solaris 2.2. This issue affects some unknown processing of the file /dev/audio of the component Audio Device Handler. Executing a manipulation can lead to improper privilege management.
This vulnerability is handled as CVE-1999-1137. It is possible to launch the attack on the local host. There is not any exploit available. This vulnerability has historical importance owing to its background and reception.
You should upgrade the affected component.
GHSA
GHSA-whwh-8wm3-8f72: The permissions for the /dev/audio device on Solaris 2
ghsa_unreviewed·2022-04-30
CVE-1999-1137 [LOW] GHSA-whwh-8wm3-8f72: The permissions for the /dev/audio device on Solaris 2
The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/122&type=0&nav=sec.sbahttp://www.ciac.org/ciac/bulletins/e-01.shtmlhttp://www.osvdb.org/6436https://exchange.xforce.ibmcloud.com/vulnerabilities/549http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/122&type=0&nav=sec.sbahttp://www.ciac.org/ciac/bulletins/e-01.shtmlhttp://www.osvdb.org/6436https://exchange.xforce.ibmcloud.com/vulnerabilities/549
1993-10-01
Published