CVE-1999-0231: Buffer Overflow
Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Seattle Labs Slmailfrom your environment.If the mail service is not required, uninstall Seattle Labs Slmail to eliminate exposure to the VRFY buffer overflow vulnerability.
- Configuration
Disable or configure the SMTP VRFY command handling so the server ignores or rejects VRFY requests (prevent processing of long VRFY inputs that can trigger the buffer overflow).
Seattle Labs Slmail / IP-Switch IMail VRFY command handling = disabled - Compensating control
Restrict access to the SMTP service (TCP port 25) at the network perimeter using firewall rules or ACLs to only trusted hosts and/or place an application-layer firewall/WAF in front of the mail server to block malformed or overlong VRFY commands.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0231?
CVE-1999-0231 is classified as a high severity vulnerability due to its potential to cause denial of service and possible remote access.
How do I fix CVE-1999-0231?
To fix CVE-1999-0231, update the IP-Switch IMail or Seattle Labs Slmail software to the latest version that addresses this buffer overflow issue.
What systems are affected by CVE-1999-0231?
CVE-1999-0231 affects the IP-Switch IMail and Seattle Labs Slmail version 2.6 packages.
What type of vulnerability is CVE-1999-0231?
CVE-1999-0231 is a buffer overflow vulnerability caused by a long VRFY command.
What are the risks associated with CVE-1999-0231?
The risks associated with CVE-1999-0231 include denial of service and the potential for unauthorized remote access to the affected systems.