Junglewise Threat Intelligence

CVE-1999-0019: Sun Solaris arbitrary file creation and deletion in rpc.statd

CVE-1999-0019 · Severity: medium · CVSS 5 · Published 1996-04-24

Vendors: Sun Microsystems.

Executive brief

A vulnerability in the rpc.statd service, a component used for network file locking and status monitoring, allows remote attackers to create or delete files on the system. This could lead to data loss or system instability by tampering with critical configuration files. The issue stems from the service incorrectly processing malformed information sent over the network.

Technical details

The rpc.statd daemon, part of the Network Status Monitor (NSM) protocol, contains a vulnerability that allows for arbitrary file creation or deletion. By sending specially crafted RPC requests containing invalid information, a remote unauthenticated attacker can manipulate files on the host system. This is likely due to insufficient validation of input used in file system operations within the statd process. The vulnerability is exploitable over the network without user interaction. Sun Microsystems addressed this issue in early security bulletins for affected Solaris versions.

Affected products

  • Sun Microsystems Solaris

Timeline

  • 1996-04-24: disclosed
  • 1996-04-24: advisory

References