Junglewise Threat Intelligence

CVE-1999-1467: Sun Microsystems SunOS arbitrary command execution in rcp

CVE-1999-1467 · Severity: critical · CVSS 10 · Published 1989-10-26

Vendors: Sun Microsystems.

Executive brief

A critical vulnerability in the remote file copy (rcp) utility of SunOS 4.0.x allows unauthorized users to take complete control of a system. By exploiting a flaw in how the system handles remote requests from trusted hosts, an attacker can execute commands with the highest level of administrative privileges (root). This could lead to total data theft, system destruction, or the installation of persistent backdoors.

Technical details

The rcp (remote copy) utility in SunOS 4.0.x contains a vulnerability that allows remote command execution with root privileges. The flaw is triggered when a request originates from a 'trusted host' (as defined in system configuration files like /etc/hosts.equiv or .rhosts). The root cause is reportedly related to the configuration or handling of the 'nobody' user account during remote operations. An attacker on a trusted network can leverage this to bypass authentication and execute arbitrary shell commands. This vulnerability was originally identified in 1989 and is addressed in vendor-specific patches from that era.

Affected products

  • Sun Microsystems SunOS 4.0.x

Timeline

  • 1989-10-26: disclosed: Initial disclosure and CERT advisory CA-1989-07 published.
  • 1999-12-30: advisory: CVE-1999-1467 assigned.

References