CVE-1999-0212: High severity Sun SunOS vulnerability
Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SunOS/rpc.mountdfrom your environment.Remove or uninstall rpc.mountd if the NFS mount service is not required.
- Configuration
Disable rpc.mountd on affected systems if NFS mount service is not required to prevent rpc.mountd from generating error messages that reveal files.
rpc.mountd (Solaris / SunOS) enabled = false - Compensating control
Restrict network access to rpc.mountd (RPC/portmapper endpoints) to trusted hosts using firewall rules or network ACLs to prevent remote attackers from querying the service.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0212?
CVE-1999-0212 is classified as a medium severity vulnerability.
How can I mitigate CVE-1999-0212?
To mitigate CVE-1999-0212, configure rpc.mountd to minimize error messages and restrict remote access.
What software is affected by CVE-1999-0212?
CVE-1999-0212 affects Solaris 5.0 and potentially other versions of SunOS.
What type of attack does CVE-1999-0212 enable?
CVE-1999-0212 enables remote attackers to gain information about files on the server.
Is there a patch available for CVE-1999-0212?
Yes, Sun has released updates to address CVE-1999-0212, and systems should be updated to the latest patch level.