CVE-1999-1080
published 1995-05-10CVE-1999-1080: rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could…
PriorityP416high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.35%
27.4th percentile
rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Sun Solaris 2.5/2.5.1/7.0 Setuid File rmmount.conf privileges management (XFDB-8350 / BID-250)
vuldb·2026-04-16·CVSS 7.2
CVE-1999-1080 [HIGH] Sun Solaris 2.5/2.5.1/7.0 Setuid File rmmount.conf privileges management (XFDB-8350 / BID-250)
A vulnerability identified as problematic has been detected in Sun Solaris 2.5/2.5.1/7.0. The affected element is an unknown function of the file rmmount.conf of the component Setuid File Handler. Performing a manipulation results in improper privilege management.
This vulnerability is identified as CVE-1999-1080. The attack is only possible with local access. There is not any exploit available.
You should upgrade the affected component.
GHSA
GHSA-jcp7-fq4x-xq6w: rmmount in SunOS 5
ghsa_unreviewed·2022-04-30
CVE-1999-1080 [HIGH] GHSA-jcp7-fq4x-xq6w: rmmount in SunOS 5
rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=92633694100270&w=2http://marc.info/?l=bugtraq&m=93971288323395&w=2http://www.securityfocus.com/bid/250https://exchange.xforce.ibmcloud.com/vulnerabilities/8350http://marc.info/?l=bugtraq&m=92633694100270&w=2http://marc.info/?l=bugtraq&m=93971288323395&w=2http://www.securityfocus.com/bid/250https://exchange.xforce.ibmcloud.com/vulnerabilities/8350
1995-05-10
Published