Junglewise Threat Intelligence

CVE-1999-0078: Sun Microsystems pcnfsd command injection and file permission manipulation

CVE-1999-0078 · Severity: low · CVSS 1.9 · Published 1996-04-18

Vendors: Sun Microsystems.

Executive brief

A vulnerability in the pcnfsd service, which handles authentication and printing for PC clients on Unix networks, allows local users to gain unauthorized control over files. An attacker with access to the system could change file permissions or run their own commands, potentially leading to the theft of sensitive data or a full system takeover. This affects older Unix-based systems like Solaris and SunOS.

Technical details

The pcnfsd (rpc.pcnfsd) daemon contains a vulnerability where it fails to properly sanitize or validate arguments passed during Remote Procedure Calls (RPC). A local attacker can exploit this by crafting specific RPC requests that include malicious arguments, leading to unauthorized file permission changes (chmod) or arbitrary command execution. The vulnerability is primarily reachable by local users on the system. While the CVSS 2.0 score is low (1.9), the impact includes potential privilege escalation if the daemon runs with elevated privileges. This issue was historically identified in SunOS and Solaris environments.

Affected products

  • Sun Microsystems pcnfsd (rpc.pcnfsd) Solaris 2.4, 2.5; SunOS 5.4, 5.5

Timeline

  • 1996-04-18: disclosed: Initial publication date in NVD

References