CVE-1999-0204: Critical severity Eric Allman Sendmail vulnerability
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sendmail 8.6.9from your environment.If running Sendmail 8.6.9 and it is not required, stop and uninstall the Sendmail 8.6.9 instance.
- Configuration
Disable ident support in Sendmail (turn off ident/identd integration) to prevent exploitation via ident.
Sendmail ident = disabled - Compensating control
Restrict or block access to ident/identd and limit exposure of Sendmail services at the network perimeter (firewall/ACLs) to prevent remote exploitation.
- Operational
If Sendmail 8.6.9 was exposed, assume possible root compromise: investigate systems for signs of compromise, restore from known-good backups or rebuild, and rotate credentials and keys as appropriate.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0204?
CVE-1999-0204 is considered a high severity vulnerability due to the potential for remote attackers to execute root commands.
How do I fix CVE-1999-0204?
To fix CVE-1999-0204, it is recommended to upgrade Sendmail to a version later than 8.6.9.
What kind of attacks does CVE-1999-0204 expose systems to?
CVE-1999-0204 allows attackers to execute arbitrary root commands, putting systems at significant risk.
Which versions of Sendmail are affected by CVE-1999-0204?
Sendmail version 8.6.9 is the specific version affected by CVE-1999-0204.
Is CVE-1999-0204 still relevant today?
While CVE-1999-0204 is an older vulnerability, it remains relevant for legacy systems that still run vulnerable versions of Sendmail.