Junglewise Threat Intelligence

CVE-1999-0190: Sun Solaris arbitrary file overwrite in rpcbind

CVE-1999-0190 · Severity: high · CVSS 7.2 · Published 1998-04-08

Vendors: Sun Microsystems.

Executive brief

A vulnerability in the Solaris rpcbind service allows a local user to overwrite critical system files. This service is responsible for mapping RPC services to network addresses. By exploiting this flaw, an attacker can gain full administrative control (root access) over the affected system, potentially leading to total data loss or system takeover.

Technical details

The rpcbind utility in Sun Solaris contains a vulnerability that allows for arbitrary file overwriting. This is typically classified as an insecure file handling or symlink-style vulnerability within the rpcbind process, which runs with elevated privileges. A local attacker can leverage this flaw to modify system-critical files, leading to a full privilege escalation to root. The vulnerability affects Solaris versions 2.3 through 2.6. Patches were historically provided by Sun Microsystems in security bulletin 167.

Affected products

  • Sun Microsystems Solaris 2.3, 2.4, 2.5, 2.5.1, 2.6
  • Sun Microsystems SunOS 5.3, 5.4, 5.5, 5.5.1

Timeline

  • 1998-04-08: disclosed
  • 1998-04-08: advisory

References