CVE-1999-0687: High severity CDE CDE vulnerability

Published Sep 13, 1999
·
Updated

The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.

Affected Software

33 affected components
CDE CDE=1.0.1
CDE CDE=1.0.2
CDE CDE=1.1
CDE CDE=2.1
CDE CDE=1.2
CDE CDE=2.120
CDE CDE=2.0
IBM AIX=4.3.2
IBM AIX=4.3
Sun SunOS=5.3
IBM AIX=4.2.1
Sun SunOS=4.1.4
Sun Solaris=2.4
Digital Unix=4.0d
Sun Solaris=2.5.1
Sun Solaris=2.5
IBM AIX=4.1.4
IBM AIX=4.2
Digital Unix=4.0f
IBM AIX=4.1.5
Sun SunOS=5.7
Sun SunOS=5.5
Sun Solaris=7.0
IBM AIX=4.1.1
Sun SunOS=5.4
Sun SunOS=5.5.1
IBM AIX=4.1.2
IBM AIX=4.3.1
Sun SunOS=4.1.3u1
IBM AIX=4.1
IBM AIX=4.1.3
Sun Solaris=2.6
Sun SunOS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove ToolTalk ttsession daemon from your environment.

    If the daemon is not required, uninstall or disable the ToolTalk ttsession daemon to eliminate exposure to remote command execution via weak RPC authentication.

  2. Configuration

    Configure the ttsession daemon to stop using weak RPC authentication: enable strong RPC authentication mechanisms if available, or disable RPC-based access for the daemon.

    ToolTalk ttsession daemon RPC authentication = use strong authentication or disable RPC access
  3. Compensating control

    Restrict network access to the ttsession daemon: block or limit incoming RPC connections using host-based firewalls, network ACLs, or perimeter firewalls so only trusted management hosts can reach the service.

  4. Operational

    Assume possible compromise if the service was exposed: review system and audit logs for unauthorized command execution, isolate affected hosts, and perform incident response and remediation as needed.

Event History

Sep 13, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-0687?

CVE-1999-0687 is classified as a high severity vulnerability due to its potential to allow remote command execution.

2

How do I fix CVE-1999-0687?

To fix CVE-1999-0687, update the affected ToolTalk ttsession daemon to a version that implements stronger RPC authentication.

3

Which software versions are affected by CVE-1999-0687?

CVE-1999-0687 affects ToolTalk versions 1.0.1, 1.0.2, 1.1, 1.2, 2.0, and various versions of IBM AIX and Sun Solaris.

4

What is the risk associated with CVE-1999-0687?

The risk associated with CVE-1999-0687 includes unauthorized remote command execution by attackers exploiting weak RPC authentication.

5

Is CVE-1999-0687 still relevant today?

While CVE-1999-0687 may seem outdated, its implications are still relevant as many systems may still operate on affected software versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203