CVE-1999-0190: High severity Sun SunOS vulnerability
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
rpcbind (Solaris)from your environment.If rpcbind is not required in your environment, uninstall or remove the rpcbind package/service to eliminate the vulnerable component.
- Configuration
Disable or stop the rpcbind service on affected Solaris/SunOS systems until an official patch is available to prevent exploitation that can overwrite files and yield root access.
rpcbind (Solaris) service_enabled = false - Compensating control
Restrict network access to RPC services (e.g., port 111/tcp and related RPC ports) using firewall rules, network ACLs, or host-based firewalls so only trusted hosts can reach rpcbind.
- Operational
Assume possible compromise where rpcbind was exposed: audit systems for signs of arbitrary file modification or root compromise, restore affected systems from known-good backups if compromise is confirmed, and rotate administrative credentials/keys.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0190?
CVE-1999-0190 has a high severity rating due to its potential to allow attackers to gain root access through file overwrites.
How do I fix CVE-1999-0190?
To fix CVE-1999-0190, it is recommended to update or patch the affected Solaris versions as provided by the vendor.
Which systems are affected by CVE-1999-0190?
CVE-1999-0190 affects various versions of SunOS and Solaris operating systems, including 5.3, 2.4, 2.5.1, 2.5, 5.4, 5.5, 5.5.1, and 2.6.
What type of attack does CVE-1999-0190 enable?
CVE-1999-0190 enables an attacker to exploit the rpcbind service to overwrite arbitrary files, leading to potential unauthorized access to the system.
Is CVE-1999-0190 still a concern today?
While CVE-1999-0190 was discovered many years ago, it remains a concern for legacy systems that have not been updated or patched.