CVE-1999-0085: Buffer Overflow
Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
rwhodfrom your environment.Uninstall or remove the rwhod (rwho) daemon/package from systems where it is not required.
- Configuration
Disable the rwhod (rwho) daemon/service on affected systems to prevent processing of remote UDP hostname packets that can trigger the buffer overflow.
rwhod (rwho daemon) on FreeBSD Kernel, IBM AIX, NetBSD current enabled = false - Compensating control
At network boundaries and host firewalls, block or filter incoming UDP packets destined for the rwhod service and restrict access to trusted management hosts until an upstream vendor patch or fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0085?
CVE-1999-0085 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-1999-0085?
To mitigate CVE-1999-0085, it is recommended to upgrade to a fixed version of the affected software or apply necessary patches.
Which systems are affected by CVE-1999-0085?
CVE-1999-0085 affects AIX 4.2, FreeBSD 6.2-stable, and NetBSD 2.0.4.
What type of attack does CVE-1999-0085 enable?
CVE-1999-0085 allows remote attackers to execute arbitrary code through a specially crafted UDP packet.
Is CVE-1999-0085 still relevant today?
While CVE-1999-0085 is an older vulnerability, it is still relevant for systems that are not updated or decommissioned.