Junglewise Threat Intelligence

CVE-1999-0298: Slackware and SunOS ypbind file overwrite via path traversal

CVE-1999-0298 · Severity: high · CVSS 7.5 · Published 1997-02-05

Technologies: Slackware Linux. Vendors: Sun Microsystems, Slackware.

Executive brief

A vulnerability exists in the ypbind service, a component used for managing network information and user accounts on older Linux and SunOS systems. When specific configuration options are enabled, attackers can exploit the service to overwrite critical system files. This could lead to a complete system takeover, data loss, or permanent disruption of operations.

Technical details

The ypbind daemon in Slackware Linux and SunOS contains a path traversal vulnerability when the -ypset or -ypsetme command-line options are enabled. These options are intended to allow the NIS domain binding to be changed, but they fail to properly sanitize input. An attacker can use '..' (dot dot) sequences to escape intended directories and overwrite arbitrary files on the system. This attack can be carried out both locally and over the network without authentication, potentially leading to unauthorized privilege escalation or system compromise.

Affected products

  • Slackware Slackware Linux
  • Sun Microsystems SunOS

Timeline

  • 1997-02-05: disclosed

References

Related threats