CVE-1999-0235: Buffer Overflow
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
NCSA HTTPdfrom your environment.Uninstall or stop NCSA HTTPd instances running version 1.4.1 or earlier until a patched release is available.
- Compensating control
Block or restrict external network access to the NCSA HTTPd service using firewall rules or network ACLs to prevent remote access until a patch is available.
- Operational
Investigate systems running NCSA HTTPd version 1.4.1 and earlier for signs of compromise; if compromise is suspected, isolate affected hosts and rotate any potentially exposed credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0235?
CVE-1999-0235 is considered a critical vulnerability due to the potential for remote exploitation.
How do I fix CVE-1999-0235?
To fix CVE-1999-0235, upgrade NCSA WebServer to version 1.4.2 or later.
What versions of NCSA WebServer are affected by CVE-1999-0235?
CVE-1999-0235 affects NCSA WebServer versions 1.3, 1.4, and 1.4.1.
What type of vulnerability is CVE-1999-0235?
CVE-1999-0235 is a buffer overflow vulnerability that allows for remote access.
Can CVE-1999-0235 be exploited remotely?
Yes, CVE-1999-0235 can be exploited remotely, enabling an attacker to gain unauthorized access.