CVE-1999-0298: High severity Sun Sunos vulnerability
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove the -ypset and -ypsetme flags from ypbind startup configuration/init scripts on affected Slackware Linux and SunOS systems so ypbind is not started with these options; after changing the startup configuration, restart or stop/start the ypbind service to apply the change.
ypbind (Slackware Linux and SunOS) startup options = do not enable -ypset or -ypsetme
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0298?
CVE-1999-0298 is classified as a high-severity vulnerability due to its potential for local and remote exploitation.
How do I fix CVE-1999-0298?
To fix CVE-1999-0298, it's recommended to disable the -ypset and -ypsetme options in ypbind or upgrade to a patched version of the software.
What systems are affected by CVE-1999-0298?
CVE-1999-0298 affects Slackware Linux versions 2.1, 2.2, and 2.3, as well as SunOS versions 4.1.3 and 4.1.4.
What is the nature of the attack in CVE-1999-0298?
The attack associated with CVE-1999-0298 involves using a dot dot (..) technique to overwrite files on vulnerable systems.
Is exploitation of CVE-1999-0298 straightforward?
Yes, exploitation of CVE-1999-0298 can be straightforward for attackers with access to the vulnerable systems.