Junglewise Threat Intelligence

CVE-1999-0300: Sun Solaris nis_cachemgr rogue server injection in NIS+

CVE-1999-0300 · Severity: high · CVSS 7.5 · Published 1997-10-01

Vendors: Sun Microsystems.

Executive brief

A vulnerability in the Solaris NIS+ directory service allows unauthorized users to add malicious servers to the network's trusted cache. This could allow an attacker to intercept sensitive information or provide fraudulent data to systems relying on the directory service for authentication and configuration. This poses a significant risk to the integrity of the corporate network environment and the security of user credentials.

Technical details

The nis_cachemgr daemon, which maintains a cache of NIS+ server locations for Solaris clients, fails to properly validate or restrict updates to its cache. A remote, unauthenticated attacker can send crafted packets to the daemon to register a rogue NIS+ server. Once the malicious server is added to the cache, client systems may query it for sensitive information such as password hashes or network configuration data. This can lead to a complete compromise of the NIS+ domain's integrity and confidentiality. The vulnerability affects Solaris versions 2.3 through 2.5.1.

Affected products

  • Sun Microsystems Solaris 2.3, 2.4, 2.5, 2.5.1
  • Sun Microsystems SunOS 5.3, 5.4, 5.5, 5.5.1

Timeline

  • 1997-10-01: disclosed: Initial publication date in NVD

References