CVE-1999-0174: Medium severity Netscape Communicator vulnerability
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Netscape Communicator view-source CGIfrom your environment.Uninstall or remove the view-source CGI script from the server, or remove execute permissions for the script so it cannot be invoked.
- Configuration
Disable the view-source CGI program (remove or disable the CGI mapping in the web server configuration) to prevent directory-traversal (.. ) attacks.
Netscape Communicator view-source CGI enabled = false - Compensating control
Restrict access to the view-source CGI (for example via web server access controls, web application firewall rules, or firewall/ACLs) to trusted administrative hosts only until the vulnerable component is removed or fixed.
- Operational
Review web server access logs for requests to the view-source CGI and for unexpected file reads; investigate potential information disclosure and, if sensitive data may have been exposed, take appropriate remediation such as credential rotation and notifying impacted parties.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0174?
CVE-1999-0174 is considered a high-severity vulnerability that allows remote attackers to read arbitrary files on affected systems.
How do I fix CVE-1999-0174?
To fix CVE-1999-0174, upgrade to a patched version of Netscape Communicator beyond 4.51 where this vulnerability is resolved.
What versions of Netscape Communicator are affected by CVE-1999-0174?
CVE-1999-0174 affects Netscape Communicator versions 4.0 through 4.51.
How does the attack work in CVE-1999-0174?
The attack in CVE-1999-0174 exploits the view-source CGI program using a dot dot (..) path traversal to access restricted files.
Can I still use Netscape Communicator if I am affected by CVE-1999-0174?
Using an affected version of Netscape Communicator is risky as it exposes systems to potential attacks, and it is highly recommended to upgrade to a secure version.