Junglewise Threat Intelligence

CVE-1999-0022: Sun Solaris rdist buffer overflow in expstr function

CVE-1999-0022 · Severity: high · CVSS 7.8 · Published 1996-07-03

Vendors: Sun Microsystems.

Executive brief

A security vulnerability exists in the 'rdist' utility, a tool used in older Unix-based systems to maintain identical copies of files across multiple hosts. A local user with limited access can exploit this flaw to gain full administrative (root) control over the system. This could lead to complete unauthorized access to all data and system functions.

Technical details

A buffer overflow vulnerability exists in the rdist utility within the expstr() function. The flaw is triggered when processing specially crafted input, allowing a local attacker to overwrite memory. Because rdist often runs with elevated privileges (setuid root) to perform file synchronization tasks, an attacker can exploit this overflow to execute arbitrary code and escalate their privileges to root. The vulnerability affects multiple versions of SunOS and Solaris.

Affected products

  • Sun Microsystems Solaris 2.0, 2.1, 2.2, 2.3, 2.4, 4.1.1, 4.1.2, 4.1.3u1
  • Sun Microsystems SunOS 5.0, 5.1, 5.2, 5.3, 5.4, 4.1.1, 4.1.2, 4.1.3u1

Timeline

  • 1996-07-03: disclosed: Initial publication date

References