CVE-1999-0019: Medium severity NCR Mp-ras vulnerability

Published Apr 24, 1996
·
Updated

Delete or create a file via rpc.statd, due to invalid information.

Affected Software

20 affected components
NCR Mp-ras=3.0
NCR Mp-ras=2.03
SGI IRIX=6.1
Data General Dg Ux=4.11
SCO OpenServer=5.0
Sun SunOS=5.5
Sun SunOS=5.3
Sun SunOS=4.1.4
SCO Open Desktop=3
SCO OpenServer=3.0
Sun SunOS=5.5
Nighthawk Cx Ux
Sun SunOS=5.4
SCO UnixWare=2
Nighthawk Powerux
Sun SunOS=5.4
Sun SunOS=4.1.3
IBM AIX=4.1
IBM AIX=3.2
SCO Open Desktop=2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove rpc.statd from your environment.

    Uninstall or stop the rpc.statd service on affected hosts when it is not needed to eliminate the attack surface that allows file creation/deletion.

  2. Configuration

    Disable rpc.statd (the RPC status monitor) if it is not required to prevent creation or deletion of files via malformed/invalid information.

    rpc.statd enabled = false
  3. Compensating control

    Restrict network access to RPC services (rpc.statd/rpcbind) using firewall rules or ACLs so that only trusted hosts can reach them.

Event History

Apr 24, 1996
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 29, 1999
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0019?

CVE-1999-0019 is classified as a moderate severity vulnerability.

2

How do I fix CVE-1999-0019?

To mitigate CVE-1999-0019, you should disable the rpc.statd service if it is not needed.

3

What are the consequences of CVE-1999-0019?

CVE-1999-0019 may allow unauthorized file creation or deletion on affected systems.

4

Which software versions are affected by CVE-1999-0019?

CVE-1999-0019 affects multiple versions of NCR MP-RAS, SGI IRIX, Data General DG/UX, Xinuos OpenServer, and Sun SunOS.

5

Is CVE-1999-0019 still a concern today?

While CVE-1999-0019 is known since 1999, it may still pose a risk to legacy systems that have not been updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203