CVE-1999-0046: Buffer Overflow
Buffer overflow of rlogin program using TERM environmental variable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
rloginfrom your environment.Uninstall the rlogin program if it is not required. If removal is not immediately possible, stop and disable the service until a vendor fix is available.
- Configuration
Disable the rlogin/rlogind service to prevent exploitation of the TERM environment variable buffer overflow.
rlogin enabled = false - Compensating control
Restrict network access to rlogin services using network or host-based firewalls (allow only trusted hosts) to reduce exposure to remote exploitation.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0046?
CVE-1999-0046 is considered a high-severity vulnerability due to the potential for remote code execution through the buffer overflow.
How do I fix CVE-1999-0046?
To fix CVE-1999-0046, it is recommended to update the affected rlogin program to a version that eliminates the buffer overflow vulnerability.
Which systems are affected by CVE-1999-0046?
CVE-1999-0046 affects multiple systems including various versions of BSDI BSD OS, FreeBSD, HP-UX, IBM AIX, Oracle Solaris, and others.
What are the potential impacts of exploiting CVE-1999-0046?
Exploitation of CVE-1999-0046 could allow an attacker to execute arbitrary code with the privileges of the rlogin program.
Is CVE-1999-0046 still relevant today?
While CVE-1999-0046 is an older vulnerability, it remains relevant for legacy systems still in use that rely on the vulnerable rlogin feature.