Junglewise Threat Intelligence

CVE-1999-0167: Sun Microsystems SunOS NFS file handle prediction vulnerability

CVE-1999-0167 · Severity: medium · CVSS 4.6 · Published 1991-12-06

Technologies: Sunos. Vendors: Sun Microsystems, Sun.

Executive brief

A vulnerability in SunOS allows unauthorized users to access files stored on a network file system. By guessing specific file identifiers, an attacker can bypass security controls to read or modify sensitive data. This could lead to the exposure of confidential information or the unauthorized alteration of system files.

Technical details

The vulnerability stems from the predictable generation of NFS file handles in SunOS. NFS (Network File System) uses these handles to identify files and directories; because they are not sufficiently random or cryptographically secure, an attacker can guess valid handles. This allows a local attacker to bypass standard access controls and interact with the exported file system. Successful exploitation grants unauthorized read, write, or delete permissions on the affected files. This issue is a classic example of weak identifier generation in early network protocols.

Affected products

  • Sun Microsystems SunOS

Timeline

  • 1991-12-06: disclosed: Initial publication date in NVD

References

Related threats