CVE-1999-0099: Buffer Overflow
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
syslog utilityfrom your environment.Stop or uninstall the syslog utility/service on affected systems until a vendor-supplied patch is available, or otherwise disable remote reception of syslog messages if uninstall is not feasible.
- Compensating control
Restrict network access to the syslog service on affected hosts. Block or limit remote access via firewall/ACLs so only trusted management networks or hosts can reach syslog functionality.
- Operational
Assume potential compromise where the vulnerable syslog utility was reachable: audit affected systems for indicators of compromise, and remediate any findings.
- Operational
Rotate credentials, keys, and administrative passwords on systems that may have been exposed or accessed via the vulnerable syslog utility.
- Operational
Monitor vendor security advisories for BSDI BSD/OS, Convex 3D / convex spp-ux, Cray UNICOS, IBM AIX, Oracle Solaris and ZFS, and SunOS and apply vendor-provided patches or updates when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0099?
CVE-1999-0099 has been classified as a high severity vulnerability due to its potential to allow local or remote attackers to gain root privileges.
How do I fix CVE-1999-0099?
To fix CVE-1999-0099, it is recommended to update the affected software packages to the latest version that patches the buffer overflow vulnerability.
Which systems are affected by CVE-1999-0099?
CVE-1999-0099 affects multiple versions of BSDi, Convex OS, Cray UNICOS, IBM AIX, and Sun Solaris.
Can CVE-1999-0099 be exploited remotely?
Yes, CVE-1999-0099 can be exploited remotely if the vulnerable syslog service is exposed to an untrusted network.
What could an attacker do if they exploit CVE-1999-0099?
If exploited, an attacker could execute arbitrary code with root privileges, potentially compromising the entire system.