First published: Wed Oct 01 1997(Updated: )
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris SPARC | =2.4 | |
Oracle Solaris SPARC | =2.5 | |
Oracle Solaris SPARC | =2.5.1 | |
Sun SunOS | =4.1.3u1 | |
Sun SunOS | =4.1.4 | |
Sun SunOS | =5.3 | |
Sun SunOS | =5.4 | |
Sun SunOS | =5.5 | |
Sun SunOS | =5.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0185 is considered a critical vulnerability due to its potential for remote command execution.
CVE-1999-0185 allows remote users to connect from an FTP server's data port to an rlogin server, potentially executing arbitrary commands on a trusted host.
CVE-1999-0185 affects multiple versions including Solaris 2.4, 2.5, 2.5.1, and SunOS versions 4.1.3u1 through 5.5.1.
To mitigate CVE-1999-0185, it is recommended to restrict rlogin access and apply any available patches for the affected Solaris and SunOS versions.
Yes, there are known exploitation techniques for CVE-1999-0185 that utilize the FTP and rlogin connection vulnerabilities.