CVE-1999-0320: Critical severity Sun SunOS vulnerability
SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SunOS rpc.cmsdfrom your environment.If the rpc.cmsd component is not required, uninstall or remove it; otherwise ensure the service is stopped and disabled.
- Configuration
Disable or stop the rpc.cmsd service until a vendor patch is available to prevent exploitation.
SunOS rpc.cmsd enabled = false - Compensating control
Restrict network access to the rpc.cmsd service using firewall rules or ACLs so only trusted management hosts can reach it.
- Operational
If there is any possibility the system was targeted, investigate for signs of compromise, restore overwritten files from trusted backups, and rotate system and administrative credentials after remediation.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0320?
CVE-1999-0320 is considered a critical vulnerability as it allows attackers to obtain root access to the system.
How do I fix CVE-1999-0320?
To fix CVE-1999-0320, update your SunOS or Solaris systems to the latest available patch provided by Oracle.
Which versions of Solaris are affected by CVE-1999-0320?
CVE-1999-0320 affects Solaris versions 2.4, 2.5, 2.5.1, 4.1.3u1, 4.1.4, 5.3, 5.4, 5.5, and 5.5.1.
What specific file access does CVE-1999-0320 exploit?
CVE-1999-0320 exploits vulnerabilities in rpc.cmsd, allowing arbitrary file overwriting.
What can be the potential consequences of CVE-1999-0320 if exploited?
If CVE-1999-0320 is exploited, attackers could gain complete control of the system with root privileges.