CVE-1999-0977: Buffer Overflow
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGTPROCSERVICE request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Stop and disable the sadmind (NETMGT) service on affected Solaris/SunOS systems to prevent processing of NETMGT_PROC_SERVICE requests until a vendor fix is available.
Solaris sadmind (NETMGT daemon) sadmind service = disabled - Compensating control
Restrict network access to systems running sadmind: block or limit access to the management/NETMGT service at the network perimeter and internal firewalls, and permit only trusted management hosts or isolated management networks until remediation is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0977?
CVE-1999-0977 is considered to be critical as it allows remote attackers to gain root privileges.
How do I fix CVE-1999-0977?
To fix CVE-1999-0977, apply the patch provided by Oracle for the affected Solaris versions.
Which versions of Solaris are affected by CVE-1999-0977?
CVE-1999-0977 affects Solaris versions 2.5, 2.5.1, 2.6, 7.0, and certain SunOS versions.
What impact does CVE-1999-0977 have on affected systems?
The impact of CVE-1999-0977 is that an attacker can execute arbitrary code with root privileges, compromising system security.
Is CVE-1999-0977 a local or remote vulnerability?
CVE-1999-0977 is a remote vulnerability that can be exploited over the network without physical access.