CVE-1999-0974: Buffer Overflow
Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Oracle Solaris snoopfrom your environment.Uninstall or remove the snoop binary if it is not required to eliminate the vulnerable component until a patch is available.
- Configuration
Stop and disable the rpc.rquotad (rquotad) service to prevent processing of GETQUOTA requests until a vendor fix is available.
rpc.rquotad (SunOS/Oracle Solaris) service_state = disabled - Compensating control
Restrict or block network access to the rpc.rquotad service/GETQUOTA requests using firewall rules or network ACLs (allow only trusted hosts) until a vendor patch or fixed version is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0974?
CVE-1999-0974 is considered critical as it allows remote attackers to gain root privileges on affected Solaris systems.
How do I fix CVE-1999-0974?
To fix CVE-1999-0974, apply the appropriate patches provided by Oracle for the affected Solaris versions.
Which Solaris versions are affected by CVE-1999-0974?
CVE-1999-0974 affects Solaris 2.4, 2.5, 2.5.1, 2.6, 7.0, and various versions of SunOS including 5.4, 5.5, 5.5.1, and 5.7.
What type of vulnerability is CVE-1999-0974?
CVE-1999-0974 is a buffer overflow vulnerability that can be exploited via GETQUOTA requests.
Can CVE-1999-0974 be exploited remotely?
Yes, CVE-1999-0974 can be exploited remotely by attackers targeting the rpc.rquotad service.