Junglewise Threat Intelligence

CVE-1999-1419: Sun Solaris buffer overflow in nss_nisplus.so.1 library

CVE-1999-1419 · Severity: high · CVSS 7.2 · Published 1997-07-30

Vendors: Sun Microsystems.

Executive brief

A security vulnerability exists in the NIS+ component of Solaris operating systems, which is used for managing network information and directory services. An attacker who already has basic access to a system can exploit this flaw to gain full administrative (root) control. This could lead to a total compromise of the affected server, including unauthorized access to all data and the ability to disrupt operations.

Technical details

A classic buffer overflow vulnerability exists within the nss_nisplus.so.1 shared library, which is part of the Name Service Switch (NSS) implementation for NIS+ in SunOS 5.3 and 5.4 (Solaris 2.3 and 2.4). The flaw is triggered when the library handles improperly validated input, allowing a local attacker to overwrite memory. By crafting a specific exploit, a non-privileged local user can execute arbitrary code with the elevated privileges of the process calling the library, typically resulting in a full root compromise. Patches were historically released by Sun Microsystems to address this issue in the late 1990s.

Affected products

  • Sun Microsystems Solaris 2.3, 2.4

Timeline

  • 1997-07-30: disclosed: Initial publication date
  • 1997-07-30: advisory: Sun security bulletin released

References