CVE-1999-0163: High severity Eric Allman Sendmail vulnerability
In older versions of Sendmail, an attacker could use a pipe character to execute root commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
sendmailfrom your environment.Uninstall Sendmail or stop and disable the sendmail service until a vendor-supplied fix is available.
- Compensating control
Block or restrict network access to the mail service (for example, firewall rules that block inbound SMTP on port 25) and limit access to the service to trusted hosts only.
- Operational
Assume possible root compromise if the vulnerability was exploited: audit systems for unauthorized root activity, preserve logs for investigation, and rotate any potentially exposed root or service credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0163?
CVE-1999-0163 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary commands as the root user.
How do I fix CVE-1999-0163?
To fix CVE-1999-0163, you should upgrade to a patched version of Sendmail that addresses this vulnerability.
Which versions of Sendmail are affected by CVE-1999-0163?
CVE-1999-0163 affects older versions of Sendmail prior to the release of the fixes for this security issue.
What can attackers do with CVE-1999-0163?
With CVE-1999-0163, attackers can exploit the vulnerability to execute root commands on the server running the vulnerable version of Sendmail.
Is CVE-1999-0163 still relevant today?
While CVE-1999-0163 is an old vulnerability, it remains relevant for legacy systems that have not been updated or patched.