Junglewise Threat Intelligence

CVE-1999-0048: Sun Microsystems Talkd remote code execution via corrupt DNS

CVE-1999-0048 · Severity: critical · CVSS 10 · Published 1997-01-27

Vendors: Sun Microsystems.

Executive brief

Talkd is a legacy networking service used to facilitate communication between users on different systems. A critical vulnerability allows an attacker to take complete control of the server by providing malicious DNS information. This could result in the theft of sensitive data, total system shutdown, or the use of the server to launch further attacks.

Technical details

The talkd daemon is vulnerable to a remote code execution flaw triggered by the processing of malformed or 'corrupt' DNS information. The vulnerability likely stems from improper validation of hostnames or DNS records returned during a reverse lookup, leading to a buffer overflow or similar memory corruption. An unauthenticated remote attacker can exploit this by sending a request that triggers a DNS lookup of a controlled, malicious record. Successful exploitation grants the attacker arbitrary command execution with root privileges on the affected host. This issue was historically identified in SunOS and other Unix-like systems utilizing the talkd service.

Affected products

  • Sun Microsystems Talkd

Timeline

  • 1997-01-27: disclosed

References