CVE-1999-0241: Critical severity SGI IRIX vulnerability
Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict remote access to X Windows displays/servers to trusted hosts using network controls (firewall, ACLs, isolation). Block or isolate hosts running X servers from untrusted networks to prevent remote exploitation of guessable magic cookies.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0241?
CVE-1999-0241 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-1999-0241?
To fix CVE-1999-0241, ensure that magic cookies are not guessable by switching to more secure authentication methods.
What systems are affected by CVE-1999-0241?
CVE-1999-0241 affects systems running SGI IRIX, XFree86 X Server, and various versions of Oracle Solaris and SunOS.
Can CVE-1999-0241 be exploited remotely?
Yes, CVE-1999-0241 can be exploited remotely, allowing attackers to execute commands on affected systems.
What are magic cookies in the context of CVE-1999-0241?
In the context of CVE-1999-0241, magic cookies are authentication tokens used to control access to the X Windows display system.