Junglewise Threat Intelligence

CVE-1999-1258: Sun Microsystems SunOS improper access control in rpc.pwdauthd

CVE-1999-1258 · Severity: medium · CVSS 5 · Published 1991-01-15

Vendors: Sun Microsystems.

Executive brief

A security flaw in an older SunOS system component called rpc.pwdauthd allows unauthorized individuals to access the service over the network. This service is responsible for password authentication tasks, and its exposure could allow an attacker to retrieve sensitive system information. This could lead to further unauthorized access or compromise of the affected server.

Technical details

The rpc.pwdauthd daemon in SunOS 4.1.1 and earlier fails to implement sufficient access control restrictions for remote RPC requests. An unauthenticated remote attacker can connect to the daemon over the network and query it to obtain sensitive system information. This vulnerability is categorized as an information disclosure flaw resulting from improper access control on a network-facing daemon. While specific patches for these legacy versions are referenced in historical Sun security bulletins, the primary mitigation is upgrading to a supported OS version or restricting access to RPC services via network filtering.

Affected products

  • Sun Microsystems SunOS 4.1.1 and earlier

Timeline

  • 1991-01-15: disclosed: Initial publication date

References