CVE-1999-0019: Medium severity NCR Mp-ras vulnerability
Delete or create a file via rpc.statd, due to invalid information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
rpc.statdfrom your environment.Uninstall or stop the rpc.statd service on affected hosts when it is not needed to eliminate the attack surface that allows file creation/deletion.
- Configuration
Disable rpc.statd (the RPC status monitor) if it is not required to prevent creation or deletion of files via malformed/invalid information.
rpc.statd enabled = false - Compensating control
Restrict network access to RPC services (rpc.statd/rpcbind) using firewall rules or ACLs so that only trusted hosts can reach them.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0019?
CVE-1999-0019 is classified as a moderate severity vulnerability.
How do I fix CVE-1999-0019?
To mitigate CVE-1999-0019, you should disable the rpc.statd service if it is not needed.
What are the consequences of CVE-1999-0019?
CVE-1999-0019 may allow unauthorized file creation or deletion on affected systems.
Which software versions are affected by CVE-1999-0019?
CVE-1999-0019 affects multiple versions of NCR MP-RAS, SGI IRIX, Data General DG/UX, Xinuos OpenServer, and Sun SunOS.
Is CVE-1999-0019 still a concern today?
While CVE-1999-0019 is known since 1999, it may still pose a risk to legacy systems that have not been updated.