CVE-1999-0096: Medium severity SCO OpenServer vulnerability
Sendmail decode alias can be used to overwrite sensitive files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove or disable the 'decode' alias in the sendmail aliases/configuration so that the decode alias cannot be used to overwrite sensitive files.
Sendmail (on affected systems) decode alias = removed or disabled
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0096?
CVE-1999-0096 has a high severity rating due to its potential to overwrite sensitive files.
How do I fix CVE-1999-0096?
To fix CVE-1999-0096, apply the latest security patches provided by your software vendor.
What systems are affected by CVE-1999-0096?
CVE-1999-0096 affects systems including Xinuos OpenServer 5.0, 5.0.2, SCO Internet FastStart, and various versions of FreeBSD.
What are the potential risks of CVE-1999-0096?
The potential risks include unauthorized access to modify or delete critical system files.
Is there a workaround for CVE-1999-0096?
A possible workaround for CVE-1999-0096 is to disable the use of the affected Sendmail features until a patch can be applied.