CVE-1999-0213: Critical severity Sun SunOS vulnerability
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If rpcbind is not required on the affected Oracle Solaris / SunOS systems, stop and disable the rpcbind service to prevent exploitation of the libnsl vulnerability.
rpcbind service_enabled = false - Compensating control
Restrict network access to rpcbind (portmapper) to trusted hosts only using firewall rules, host-based firewall, or network ACLs to reduce exposure to the libnsl-induced denial-of-service against rpcbind.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0213?
CVE-1999-0213 is classified as a denial of service vulnerability that can severely affect system availability.
How do I fix CVE-1999-0213?
To fix CVE-1999-0213, it is recommended to apply patches provided by Sun Microsystems or upgrade to a newer version of SunOS or Solaris.
Which systems are affected by CVE-1999-0213?
CVE-1999-0213 affects SunOS versions 5.4, 5.5, 5.5.1, and Solaris 2.6.
What is the impact of exploiting CVE-1999-0213?
Exploitation of CVE-1999-0213 can lead to a denial of service condition affecting the rpcbind service.
Who is responsible for addressing CVE-1999-0213?
System administrators using affected versions of SunOS or Solaris are responsible for addressing CVE-1999-0213.