CVE-1999-0300: High severity Sun SunOS vulnerability
niscachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
nis_cachemgr (Oracle Solaris / SunOS)from your environment.Disable or uninstall the nis_cachemgr binary/daemon on affected systems to prevent it from being used to add malicious NIS+ servers until an official patch from the vendor is available.
- Configuration
Stop and disable the NIS+ service (prevent nis_cachemgr from running) on affected hosts until a vendor fix is applied.
Solaris NIS+ nis_plus_enabled = false - Compensating control
Restrict network access to NIS+/nis_cachemgr management interfaces—use firewall rules, ACLs or network segmentation to allow only trusted NIS+ servers and administrative hosts to communicate with affected systems.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0300?
CVE-1999-0300 is a high severity vulnerability that allows attackers to add malicious NIS+ servers.
How do I fix CVE-1999-0300?
To fix CVE-1999-0300, apply the latest patches from Oracle for affected Solaris and SunOS versions.
What systems are affected by CVE-1999-0300?
CVE-1999-0300 affects Solaris versions 2.4, 2.5, 2.5.1 and SunOS versions 5.3, 5.4, 5.5, and 5.5.1.
What impact can CVE-1999-0300 have?
CVE-1999-0300 can lead to unauthorized control over network information services, allowing attackers to manipulate user data.
Is CVE-1999-0300 still a threat today?
While CVE-1999-0300 was reported over two decades ago, systems still using the affected software may remain vulnerable if not updated.