Junglewise Threat Intelligence

CVE-1999-0003: Sun Solaris Tooltalk database server buffer overflow in rpc.ttdbserverd

CVE-1999-0003 · Severity: critical · CVSS 10 · Published 1998-04-01

Technologies: Sgi Irix. Vendors: Sun Microsystems, Sgi.

Executive brief

A critical vulnerability exists in the Tooltalk database server, a component used in older Unix-based operating systems for inter-application communication. An attacker can exploit this flaw to take complete control of the affected system with administrative (root) privileges. This could lead to total data loss, unauthorized access to sensitive information, and complete disruption of operations.

Technical details

The vulnerability is a classic buffer overflow within the rpc.ttdbserverd daemon, which is part of the ToolTalk message-passing system. The flaw is reachable over the network via RPC (Remote Procedure Call) without requiring authentication. By sending a specially crafted request to the Tooltalk database server, an attacker can overwrite memory to redirect execution flow. Successful exploitation results in arbitrary code execution as the root user, providing full system compromise. Patches were historically released by vendors such as Sun Microsystems and SGI.

Affected products

  • Sun Microsystems Solaris 1.1, 1.2, 2.0, 2.1, 2.2, 2.3, 2.4, 2.5, 2.5.1
  • Sun Microsystems SunOS 4.1.3, 5.0, 5.1, 5.2, 5.3, 5.4, 5.5, 5.5.1
  • SGI IRIX patches

Timeline

  • 1998-04-01: advisory: NVD Published Date
  • 1998-11-01: advisory: SGI security advisory released

References

Related threats