CVE-1999-0300: High severity Sun SunOS vulnerability

Published Oct 1, 1997
·
Updated

niscachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.

Affected Software

7 affected components
Sun SunOS=5.3
Sun Solaris=2.4
Sun Solaris=2.5.1
Sun Solaris=2.5
Sun SunOS=5.5
Sun SunOS=5.4
Sun SunOS=5.5.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove nis_cachemgr (Oracle Solaris / SunOS) from your environment.

    Disable or uninstall the nis_cachemgr binary/daemon on affected systems to prevent it from being used to add malicious NIS+ servers until an official patch from the vendor is available.

  2. Configuration

    Stop and disable the NIS+ service (prevent nis_cachemgr from running) on affected hosts until a vendor fix is applied.

    Solaris NIS+ nis_plus_enabled = false
  3. Compensating control

    Restrict network access to NIS+/nis_cachemgr management interfaces—use firewall rules, ACLs or network segmentation to allow only trusted NIS+ servers and administrative hosts to communicate with affected systems.

Event History

Oct 1, 1997
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 29, 1999
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0300?

CVE-1999-0300 is a high severity vulnerability that allows attackers to add malicious NIS+ servers.

2

How do I fix CVE-1999-0300?

To fix CVE-1999-0300, apply the latest patches from Oracle for affected Solaris and SunOS versions.

3

What systems are affected by CVE-1999-0300?

CVE-1999-0300 affects Solaris versions 2.4, 2.5, 2.5.1 and SunOS versions 5.3, 5.4, 5.5, and 5.5.1.

4

What impact can CVE-1999-0300 have?

CVE-1999-0300 can lead to unauthorized control over network information services, allowing attackers to manipulate user data.

5

Is CVE-1999-0300 still a threat today?

While CVE-1999-0300 was reported over two decades ago, systems still using the affected software may remain vulnerable if not updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203