CVE-1999-1588: Buffer Overflow
Buffer overflow in nlpsserver in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
nlps_server (Sun Solaris)from your environment.Uninstall nlps_server from affected systems if the service is not required.
- Configuration
Stop and disable the nlps_server (System V listener) service to prevent it from listening on TCP port 2766.
nlps_server (Sun Solaris) enabled = false - Compensating control
Block or filter TCP port 2766 at the network perimeter/firewall or restrict access to that port to trusted IPs to prevent remote connections to nlps_server.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1588?
CVE-1999-1588 has a critical severity rating as it allows remote attackers to execute arbitrary code as root.
How do I fix CVE-1999-1588?
To fix CVE-1999-1588, update to the latest patch or version of Sun Solaris that addresses this vulnerability.
What systems are affected by CVE-1999-1588?
CVE-1999-1588 affects Sun Solaris versions 2.4, 2.5, and 2.5.1 on x86 architecture.
What kind of attack exploits CVE-1999-1588?
CVE-1999-1588 is exploited through buffer overflow attacks via a specially crafted long string sent to TCP port 2766.
Can CVE-1999-1588 be exploited remotely?
Yes, CVE-1999-1588 can be exploited remotely by attackers targeting the vulnerable nlps_server.