Executive brief
A critical vulnerability exists in the Network File System (NFS) implementation of older Sun Microsystems operating systems. This flaw allows an attacker to manipulate the system's file cache, potentially leading to unauthorized access or modification of sensitive data stored on network drives. Successful exploitation could result in a complete compromise of the affected system's data integrity and confidentiality.
Technical details
The vulnerability is a cache poisoning flaw within the Network File System (NFS) protocol implementation in SunOS and Solaris. An unauthenticated remote attacker can exploit this by sending malicious NFS responses or packets that corrupt the local file cache. This can lead to the system serving incorrect data or allowing unauthorized file access. The root cause is a lack of sufficient validation for incoming NFS data, which allows an attacker to inject arbitrary information into the cache. This issue affects multiple legacy versions of SunOS (4.x and 5.x) and Solaris (1.x and 2.x).
Affected products
- Sun Microsystems Solaris 1.1, 1.1.1a, 1.1.2, 1.2, 2.0, 2.1, 2.2, 2.3, 2.4
- Sun Microsystems SunOS 4.1.3, 4.1.4, 5.0, 5.1, 5.2, 5.3, 5.4
Timeline
- 1997-03-01: disclosed: Initial publication date in NVD