Junglewise Threat Intelligence

CVE-1999-1118: Sun Solaris ndd denial of service via TCP/IP parameter modification

CVE-1999-1118 · Severity: low · CVSS 2.1 · Published 1998-03-11

Vendors: Sun Microsystems.

Executive brief

A vulnerability in the Solaris 2.6 operating system allows local users to disrupt network services. By using the 'ndd' utility to improperly modify TCP/IP configuration parameters, an attacker can cause a denial-of-service condition. This could lead to network instability or a complete loss of connectivity for the affected system.

Technical details

The 'ndd' utility in Solaris 2.6, which is used to examine and modify kernel configuration parameters, contains a vulnerability that allows local users to alter sensitive TCP/IP stack settings. An attacker with local access can exploit this to misconfigure network parameters, leading to a denial-of-service (DoS) state. The vulnerability stems from insufficient restrictions on which parameters can be modified by non-privileged or local users via the ndd interface. Successful exploitation results in partial loss of availability for network services. Patches were historically released by Sun Microsystems to address this issue.

Affected products

  • Sun Microsystems Solaris 2.6

Timeline

  • 1998-03-11: disclosed
  • 1998-03-11: advisory

References