Insecure Permissions on /dev/audio Device: Exploiting Microphone Monitoring Vulnerability

Insecure Permissions on /dev/audio Device: Exploiting Microphone Monitoring Vulnerability

CVE-1999-1137 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.

Learn more about our Cis Benchmark Audit For Oracle Solaris.