Junglewise Threat Intelligence

CVE-1999-0208: Sun NIS rpc.ypupdated remote command execution

CVE-1999-0208 · Severity: critical · CVSS 10 · Published 1995-12-12

Vendors: Sun Microsystems.

Executive brief

The rpc.ypupdated service, part of the Network Information Service (NIS) used for managing system configuration data across a network, contains a critical security flaw. An unauthorized remote attacker can exploit this vulnerability to execute arbitrary commands on the affected server. This could lead to a total compromise of the system, including the theft of sensitive data or a complete shutdown of network services.

Technical details

The rpc.ypupdated daemon, which handles updates to NIS maps, fails to properly validate or sanitize inputs from remote RPC requests. This lack of validation allows a remote, unauthenticated attacker to inject and execute arbitrary shell commands on the host system. The vulnerability is reachable over the network via the RPC portmapper. Successful exploitation grants the attacker the same privileges as the daemon, typically root, leading to full system compromise. This is a legacy vulnerability affecting older Unix-based systems utilizing NIS.

Affected products

  • Sun Microsystems ypupdated (NIS)

Timeline

  • 1995-12-12: disclosed

References