CVE-1999-0043: OS Command Injection
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
INN (innd) 1.5from your environment.If INN (innd) 1.5 is deployed and not required, uninstall the INN daemon or stop/disable the innd service until a vendor-supplied fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0043?
CVE-1999-0043 is categorized with a high severity due to the potential for command execution vulnerabilities.
How do I fix CVE-1999-0043?
To mitigate CVE-1999-0043, upgrade to a non-vulnerable version of INN or apply the necessary patches provided by the maintainers.
What systems are affected by CVE-1999-0043?
CVE-1999-0043 affects different versions of the ISC INN daemon including 1.4sec, 1.4sec2, 1.4unoff3, 1.4unoff4, and 1.5.
What are the risks associated with CVE-1999-0043?
The risks of CVE-1999-0043 include unauthorized command execution, which can lead to system compromise.
Are there any workarounds for CVE-1999-0043?
Temporary mitigations for CVE-1999-0043 involve disabling the features that utilize the vulnerable control messages until an update can be applied.