Vulnerability Name: | CVE-1999-0210 (CCN-487) | ||||||||
Assigned: | 1997-08-01 | ||||||||
Published: | 1997-08-01 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: SGI Security Advisory 19981005-01-PX Vulnerability in IRIX autofsd Source: CCN Type: BugTraq Mailing List, Wed, 26 Nov 1997 02:02:13 -0600 Solaris 2.5.1 automountd exploit (fwd) Source: CCN Type: BugTraq Mailing List, Mon, 4 Jan 1999 00:12:08 PST SUN almost has a clue! (automountd) Source: CCN Type: CIAC Information Bulletin J-045 Vulnerability in statd exposes vulnerability in automountd Source: MITRE Type: CNA CVE-1999-0210 Source: BUGTRAQ Type: UNKNOWN 19971126 Solaris 2.5.1 automountd exploit (fwd) Source: BUGTRAQ Type: UNKNOWN 19990103 SUN almost has a clue! (automountd) Source: CCN Type: Sun Microsystems, Inc. Security Bulletin #00151 Vulnerability in automounter Source: CCN Type: Hewlett-Packard Company Security Bulletin HPSBUX9910-104 Sec. Vulnerability regarding automountd (rev. 01) Source: CCN Type: CERT Advisory CA-1999-05 Vulnerability in statd exposes vulnerability in automountd Source: CERT Type: Patch, Third Party Advisory, US Government Resource CA-99-05 Source: CCN Type: CERT Incident Note IN-1999-04 Similar Attacks Using Various RPC Services Source: CCN Type: OSVDB ID: 947 Sun automountd Shell Metacharacter Arbitrary Command Execution Source: BID Type: UNKNOWN 235 Source: CCN Type: BID-235 Solaris automount Vulnerability Source: CCN Type: BID-729 Multiple Vendor Automountd Vulnerability Source: HP Type: UNKNOWN HPSBUX9910-104 Source: XF Type: UNKNOWN sun-automountd(487) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |