19990103 SUN almost has a clue! (automountd)mailing list
http://marc.info/?l=bugtraq&m=91547759121289&w=2 CVE-1999-0493
Sun Solaris 2.5.1 - rpc.statd rpc Call Relaying
Record summary
CVE-1999-0493 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSun Solaris 2.5.1 - rpc.statd rpc Call RelayingExploitDB exploitby anonymousNot analyzed1 file
References
600186Vendor advisory
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/186&type=0&nav=sec.sba CA-99-05Third-party advisory
http://www.cert.org/advisories/CA-99-05-statd-automountd.html J-045Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/j-045.shtml 450vdb entry
http://www.securityfocus.com/bid/450 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-1999-0493