Junglewise Threat Intelligence

CVE-1999-0185: Sun Microsystems SunOS and Solaris remote command execution in rlogin

CVE-1999-0185 · Severity: high · CVSS 7.5 · Published 1997-10-01

Vendors: Sun Microsystems.

Executive brief

A vulnerability in SunOS and Solaris operating systems allows remote attackers to execute unauthorized commands. By exploiting a trust relationship between an FTP server and an rlogin server, an attacker can gain control over the affected system. This could lead to a total compromise of the server, including the theft of sensitive data or disruption of business operations.

Technical details

This vulnerability stems from a flaw in how trust relationships are handled between FTP and rlogin services in SunOS and Solaris. An attacker can initiate a connection from a trusted FTP server's data port (typically port 20) to the rlogin daemon on a target host. Because the rlogin service may trust connections originating from specific privileged ports on trusted hosts, the attacker can bypass standard authentication mechanisms. This allows for remote command execution with the privileges of the user associated with the trust relationship. The issue affects Solaris versions 2.3 through 2.5.1 and SunOS versions 5.3 through 5.5.1.

Affected products

  • Sun Microsystems SunOS 5.3, 5.4, 5.5, 5.5.1
  • Sun Microsystems Solaris 2.3, 2.4, 2.5, 2.5.1

Timeline

  • 1997-10-01: disclosed: Initial publication date

References