CVE-1999-0005: Buffer Overflow
Arbitrary command execution via IMAP buffer overflow in authenticate command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sun iPlanet Messaging Serverfrom your environment.If IMAP functionality is not required, uninstall or disable the IMAP component of Sun iPlanet Messaging Server until a vendor fix is available.
- Remove
Remove
University of Washington UW-IMAPfrom your environment.If IMAP functionality is not required, uninstall or disable UW-IMAP until a vendor fix is available.
- Configuration
Disable the IMAP authenticate command or stop/disable the IMAP service on affected servers until a vendor-supplied fix is available.
IMAP (authenticate command) in Sun iPlanet Messaging Server / University of Washington UW-IMAP IMAP authentication/authenticate command = disabled / stop IMAP service - Compensating control
Restrict access to the IMAP service to trusted IP addresses using firewall rules or network ACLs; block or limit IMAP access from untrusted networks until the issue is remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0005?
CVE-1999-0005 is categorized as a high severity vulnerability due to the potential for arbitrary command execution.
How do I fix CVE-1999-0005?
To fix CVE-1999-0005, upgrade to a patched version of the affected software that addresses the buffer overflow issue.
Which software is affected by CVE-1999-0005?
CVE-1999-0005 affects Sun iPlanet Messaging Server version 3.55 and University of Washington IMAP version 10.234.
What type of vulnerability is CVE-1999-0005?
CVE-1999-0005 is an arbitrary command execution vulnerability caused by a buffer overflow in the IMAP authenticate command.
How can CVE-1999-0005 impact systems?
CVE-1999-0005 can allow an attacker to execute arbitrary commands on the server, compromising its integrity and security.