CVE-1999-0189: High severity Sun SunOS vulnerability
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure network filtering/firewall/ACLs block or restrict access to the high-numbered UDP port(s) on which Solaris rpcbind is listening (in addition to the standard port 111). Restrict access to rpcbind/RPC services to trusted hosts or networks.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0189?
CVE-1999-0189 is classified as a medium severity vulnerability due to the potential for exposure of services.
How do I fix CVE-1999-0189?
To fix CVE-1999-0189, it is recommended to restrict access to the high numbered UDP port used by rpcbind through firewall rules.
What systems are affected by CVE-1999-0189?
CVE-1999-0189 affects various versions of Solaris and SunOS, including Solaris 2.4, 2.5, 2.5.1, and SunOS versions 5.3 through 5.5.1.
What is the impact of CVE-1999-0189?
The impact of CVE-1999-0189 includes potential unauthorized access to services that listen on unfiltered high numbered UDP ports.
Is CVE-1999-0189 still a concern for modern systems?
While CVE-1999-0189 pertains to older systems, any legacy systems still in use may still be at risk and require attention.