CVE-1999-0008: Buffer Overflow
Buffer overflow in NIS+, in Sun's rpc.nisd program.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
NIS+ (rpc.nisd)from your environment.Uninstall or remove the NIS+ package and rpc.nisd binary on systems where NIS+ is not required.
- Configuration
Stop and disable the rpc.nisd daemon (NIS+) on affected HPE HP-UX, Oracle Solaris/ZFS, and SunOS systems until a vendor fix is available.
rpc.nisd (NIS+ service) enabled = false - Compensating control
Restrict network access to NIS+/rpc.nisd services: block NIS+ ports at the network perimeter and limit access via firewall/ACLs to only trusted management hosts or networks.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0008?
CVE-1999-0008 is classified as a critical vulnerability due to the potential for remote code execution through a buffer overflow.
How do I fix CVE-1999-0008?
To mitigate CVE-1999-0008, it is recommended to apply the relevant patches provided by HPE for HP-UX or Oracle for Solaris and SunOS.
What software versions are affected by CVE-1999-0008?
CVE-1999-0008 affects HPE HP-UX versions 10.34 and 11.00, Oracle Solaris 2.6, and Sun SunOS versions 5.3, 5.4, 5.5, and 5.5.1.
What type of vulnerability is CVE-1999-0008?
CVE-1999-0008 is a buffer overflow vulnerability that can allow attackers to execute arbitrary code on the affected systems.
Who is impacted by CVE-1999-0008?
Organizations using the affected versions of HP-UX, Solaris, or SunOS software may be significantly impacted by CVE-1999-0008.