Junglewise Threat Intelligence

CVE-1999-0320: Sun Microsystems SunOS arbitrary file overwrite in rpc.cmsd

CVE-1999-0320 · Severity: critical · CVSS 9.3 · Published 1998-03-01

Vendors: Sun Microsystems.

Executive brief

A vulnerability in the calendar manager service of SunOS allows remote attackers to gain full administrative control over the system. By exploiting this flaw, an attacker can overwrite critical system files, potentially leading to a complete system takeover or permanent data loss. This affects older Solaris environments that rely on the rpc.cmsd service for scheduling and calendar functions.

Technical details

The rpc.cmsd (Calendar Manager Service Daemon) in SunOS/Solaris contains a vulnerability that allows for arbitrary file overwriting. The flaw is accessible via the network through Remote Procedure Calls (RPC). An unauthenticated remote attacker can leverage this to overwrite sensitive system files, such as configuration files or binaries, with arbitrary data. This typically leads to a privilege escalation to root. The vulnerability affects Solaris versions 2.3 through 2.5.1.

Affected products

  • Sun Microsystems SunOS 5.3, 5.4, 5.5, 5.5.1 (Solaris 2.3, 2.4, 2.5, 2.5.1)

Timeline

  • 1998-03-01: disclosed
  • 1998-03-01: advisory

References