CVE-1999-0051: High severity GlobeTrotter Flexlm vulnerability
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
FLEXlm LicenseManagerfrom your environment.Uninstall or disable FLEXlm LicenseManager on IRIX systems if it is not required, or remove the product from affected hosts until a vendor-provided fix is available.
- Configuration
Stop and disable the FLEXlm LicenseManager service on IRIX systems (ensure it does not start on boot) until a vendor fix or patch is applied.
FLEXlm LicenseManager service_enabled = false - Compensating control
Restrict access to systems running FLEXlm LicenseManager on IRIX using network controls (firewall, ACLs, host-based firewall) to only trusted administrative IPs and management networks until the issue is remediated.
- Operational
Identify IRIX systems running FLEXlm LicenseManager versions 4.0 through 5.0; inspect for unexpected files and processes, remove or quarantine unauthorized files, terminate suspicious processes, and perform incident investigation and remediation on compromised hosts.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0051?
CVE-1999-0051 has a moderate severity rating due to its potential for arbitrary file creation and execution.
How do I fix CVE-1999-0051?
To fix CVE-1999-0051, upgrade FLEXlm License Manager to a version higher than 5.0.
Which software versions are affected by CVE-1999-0051?
CVE-1999-0051 affects FLEXlm License Manager versions 4.0 to 5.0, and various versions of SGI IRIX and Sun OS.
What kind of vulnerability is CVE-1999-0051?
CVE-1999-0051 is classified as an arbitrary file creation and program execution vulnerability.
What systems are vulnerable to CVE-1999-0051?
Systems running affected versions of FLEXlm License Manager and certain SGI IRIX and Sun OS versions are vulnerable to CVE-1999-0051.