CVE-1999-0057: High severity Eric Allman Vacation vulnerability
Vacation program allows command execution by remote users through a sendmail command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
vacationfrom your environment.Uninstall or remove the vacation program if it is not required to eliminate the vector that allows remote command execution via sendmail.
- Configuration
Disable or restrict the vacation program's ability to invoke sendmail (prevent mail-triggered execution) so remote users cannot execute commands through the sendmail path.
vacation / sendmail integration sendmail command invocation by vacation = disabled or restricted - Compensating control
Apply network or mail-path restrictions to prevent remote users from triggering sendmail execution (for example, restrict mail relay/acceptance to trusted hosts, enforce firewall rules to block untrusted sources) until the vulnerable behavior is remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0057?
CVE-1999-0057 is considered a high severity vulnerability due to the potential for command execution by remote users.
How do I fix CVE-1999-0057?
To fix CVE-1999-0057, you should apply the latest security patches for the affected software and restrict access to the vacation program.
Which software is affected by CVE-1999-0057?
CVE-1999-0057 affects various versions of the vacation program and several operating systems including FreeBSD, HP-UX, AIX, and Solaris.
What type of exploitation does CVE-1999-0057 allow?
CVE-1999-0057 allows remote command execution via the sendmail command, leading to unauthorized actions.
Is CVE-1999-0057 still relevant?
Yes, CVE-1999-0057 remains relevant as many legacy systems may still be in use and susceptible to this vulnerability.