CVE-1999-0206: Buffer Overflow
MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sendmailfrom your environment.Stop and uninstall Sendmail on affected systems if the service is not required until a vendor-fixed release is available.
- Compensating control
Block or restrict network access to mail services (e.g., SMTP ports) and administrative interfaces for hosts running Sendmail 8.8.0 or 8.8.1; allow only trusted management IPs until a fix is applied.
- Operational
Identify hosts running Sendmail 8.8.0 or 8.8.1, investigate for signs of compromise (root compromise is possible), and if compromise is suspected perform full system rebuilds and rotate credentials and keys.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0206?
CVE-1999-0206 has a critical severity rating due to its ability to provide root access.
How do I fix CVE-1999-0206?
To fix CVE-1999-0206, you should upgrade Sendmail to version 8.8.2 or later.
What systems are affected by CVE-1999-0206?
CVE-1999-0206 affects Sendmail versions 8.8.0 and 8.8.1.
What type of vulnerability is CVE-1999-0206?
CVE-1999-0206 is a buffer overflow vulnerability in Sendmail.
Can CVE-1999-0206 be exploited remotely?
Yes, CVE-1999-0206 can be exploited remotely without authentication.