CVE-1999-1225: Medium severity Digital Ultrix vulnerability

Published Aug 24, 1997
·
Updated

rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.

Affected Software

5 affected components
Digital Ultrix
Linux Linux kernel=2.6.20.1
NetBSD NetBSD=2.0.4
OpenBSD OpenBSD
Sun Solaris

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove the affected component from your environment.

    Uninstall/remove the rpc.mountd (mount daemon) or NFS server package from systems where it is not required.

  2. Configuration

    If NFS server/mountd functionality is not required, stop and disable the rpc.mountd (mount daemon) service on affected systems to prevent remote mount attempts.

    rpc.mountd enabled = false
  3. Compensating control

    Restrict access to rpc.mountd (NFS mount service) using network controls (firewall, ACLs, or host-based rules) so only trusted hosts/networks can contact the service; block mountd-related ports from untrusted networks.

  4. Operational

    Monitor and audit system and NFS logs for mount attempts and anomalous mount-related error messages that could indicate attempts to probe for file existence; investigate and remediate suspicious activity.

Event History

Aug 24, 1997
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1225?

CVE-1999-1225 is considered a moderate security vulnerability since it allows attackers to infer the existence of files on the server.

2

What types of systems are affected by CVE-1999-1225?

CVE-1999-1225 affects Linux, Ultrix, NetBSD, OpenBSD, and Oracle Solaris systems.

3

How do I fix CVE-1999-1225?

To fix CVE-1999-1225, configure the rpc.mountd service properly to restrict access and prevent information leakage.

4

Can CVE-1999-1225 be exploited remotely?

Yes, CVE-1999-1225 can be exploited by remote attackers who can attempt to mount files.

5

What kind of information can attackers gain from CVE-1999-1225?

Attackers can determine the existence of specific files on the server through varying error messages generated by the rpc.mountd service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203