CVE-1999-0050: Buffer Overflow
Buffer overflow in HP-UX newgrp program.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HP-UX newgrpfrom your environment.If the 'newgrp' program is not required, uninstall or remove the executable from systems to eliminate the vulnerable component or replace it with a safe alternative.
- Compensating control
If removal is not possible, restrict execution of the 'newgrp' binary (e.g., remove execute permissions, restrict to administrative users via file permissions or access control) until a vendor patch is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0050?
CVE-1999-0050 has a high severity due to the buffer overflow vulnerability that can lead to arbitrary code execution.
How do I fix CVE-1999-0050?
To fix CVE-1999-0050, apply the relevant patches from HPE for the affected HP-UX versions.
What HP-UX versions are affected by CVE-1999-0050?
CVE-1999-0050 affects HP-UX versions 9.00 through 10.20.
Can CVE-1999-0050 be exploited remotely?
Yes, CVE-1999-0050 can potentially be exploited remotely if an attacker can access the newgrp program.
What is the potential impact of CVE-1999-0050?
The potential impact of CVE-1999-0050 includes unauthorized access and execution of malicious code on the affected system.