CVE-1999-0042: Buffer Overflow
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
University of Washington's implementation of IMAP and POP serversfrom your environment.If the software is not required, uninstall the University of Washington IMAP/POP server implementation to eliminate exposure.
- Configuration
Disable the IMAP and POP services provided by the University of Washington implementation until a vendor-supplied fix is available.
University of Washington's implementation of IMAP and POP servers service_enabled = false - Compensating control
Restrict network access to the University of Washington IMAP and POP services to trusted hosts only (using firewall rules, network ACLs, or segmentation) until a fix can be applied.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0042?
CVE-1999-0042 is classified as a critical vulnerability due to its potential for remote code execution via a buffer overflow.
How do I fix CVE-1999-0042?
To fix CVE-1999-0042, upgrade to the latest version of the University of Washington's IMAP and POP servers that does not have this vulnerability.
What systems are affected by CVE-1999-0042?
CVE-1999-0042 affects the University of Washington POP and IMAP servers, as well as several versions of IBM AIX and Red Hat Linux.
Can CVE-1999-0042 be exploited remotely?
Yes, CVE-1999-0042 can be exploited remotely, allowing attackers to execute arbitrary code on vulnerable systems.
When was CVE-1999-0042 discovered?
CVE-1999-0042 was disclosed in 1999, highlighting long-standing vulnerabilities in the implementation of IMAP and POP protocols.