CVE-1999-0061: Medium severity BSDI Bsd Os vulnerability
File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
line printer daemon (lpd)from your environment.If lpd/print services are not required, uninstall or remove the lpd package/daemon from affected systems.
- Configuration
Stop and disable the lpd service on affected systems until a security patch or vendor guidance is available.
line printer daemon (lpd) service_enabled = false - Compensating control
Restrict network access to the lpd service (line printer daemon) using firewall rules or ACLs — allow only trusted hosts or block access entirely until a fix is applied.
- Operational
Audit systems for signs of compromise related to lpd: review logs for unauthorized file creation/deletion and remote execution, verify integrity of affected systems and printer-related files, and rebuild or restore from known-good backups if compromise is detected.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0061?
CVE-1999-0061 is considered a critical vulnerability due to its impact on file creation, deletion, and remote execution capabilities.
How do I fix CVE-1999-0061?
To fix CVE-1999-0061, users should upgrade to a patched version of the BSD line printer daemon (lpd) that mitigates this vulnerability.
What systems are affected by CVE-1999-0061?
CVE-1999-0061 affects various operating systems including BSDI, FreeBSD, OpenBSD, and specific versions of the Linux kernel.
What potential consequences does CVE-1999-0061 pose?
The consequences of CVE-1999-0061 can include unauthorized file manipulation and execution of arbitrary commands on vulnerable systems.
Is CVE-1999-0061 still relevant today?
While CVE-1999-0061 was reported over two decades ago, it remains relevant for legacy systems still utilizing vulnerable versions of lpd.