CVE-1999-0168: High severity Sun Sunos vulnerability

Published Jun 4, 1992
·
Updated

The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions.

Affected Software

2 affected components
Sun Sunos=4.1.3
Sun Sunos=4.1.3c

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove SunOS portmapper (portmap/rpcbind) from your environment.

    Stop and/or uninstall the portmapper service if it is not required on the system.

  2. Configuration

    Configure the portmapper to bind only to the loopback interface (127.0.0.1) or disable the service when not required to prevent it acting as a proxy and redirecting requests.

    SunOS portmapper (portmap/rpcbind) bind_address = 127.0.0.1 or disabled
  3. Compensating control

    Restrict network access to the portmapper service from untrusted networks (e.g., block or firewall access to the portmapper/rpcbind service) so remote hosts cannot use it as a proxy.

  4. Operational

    Audit NFS exports and currently mounted filesystems for signs of unauthorized mounts established via the portmapper; remove any unauthorized mounts and remediate export configurations as needed.

Event History

Jun 4, 1992
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 29, 1999
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0168?

CVE-1999-0168 is considered a moderate severity vulnerability that can lead to unauthorized access due to proxy behavior from the portmapper.

2

How do I fix CVE-1999-0168?

To fix CVE-1999-0168, restrict access to the portmapper service and apply available patches from your software provider.

3

What systems are affected by CVE-1999-0168?

CVE-1999-0168 affects Sun SunOS versions 4.1.3 and 4.1.3c.

4

What type of attacks can be executed using CVE-1999-0168?

CVE-1999-0168 can allow an attacker to bypass authentication and mount NFS file systems that should be restricted.

5

Is there a workaround for CVE-1999-0168?

A workaround for CVE-1999-0168 involves configuring firewall rules to limit external access to the portmapper service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203