CVE-1999-0152: High severity Data General Dg Ux vulnerability
The DG/UX finger daemon allows remote command execution through shell metacharacters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Data General DG/UX finger daemonfrom your environment.Uninstall the finger daemon from affected systems if it is not required. If removal is not possible, ensure the service is disabled.
- Configuration
Disable the finger daemon on affected DG/UX systems (prevent it from being started at boot and stop any running instance).
DG/UX finger daemon service_enabled = false - Compensating control
Block or restrict network access to the finger service (TCP port 79) at the network perimeter or host-based firewall; allow access only from trusted management hosts if required.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0152?
CVE-1999-0152 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-1999-0152?
To mitigate CVE-1999-0152, it is advised to disable the finger daemon or apply patches provided by Data General.
What software is affected by CVE-1999-0152?
CVE-1999-0152 affects the DG/UX operating system developed by Data General.
Can CVE-1999-0152 be exploited remotely?
Yes, CVE-1999-0152 can be exploited remotely, allowing attackers to execute commands on the vulnerable system.
What actions should be taken if CVE-1999-0152 is detected?
If CVE-1999-0152 is detected, it is critical to either patch the system or disable the vulnerable finger daemon immediately.