Search

published date: December 30, 1992

CVE-1999-1021 : NFS on SunOS 4.1...

Description

NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.

Product(s):

  • Sun SunOS 4.1.1
  • Sun SunOS 4.1.2
  • Sun SunOS 4.1

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-1999-1021, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-1999-1021 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?