CVE-1999-0242: High severity Slackware Slackware Linux vulnerability
Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove the affected component from your environment.
Uninstall any POP3 server/daemon from the Slackware system if POP3 functionality is not required.
- Configuration
Disable the POP3 service on affected Slackware systems (stop the POP3 daemon and disable it from starting at boot) to prevent remote access to mail files via POP3.
POP3 service enabled = false - Compensating control
Block or restrict access to POP3 ports (TCP 110 and 995) at the network perimeter or host firewall and allow access only from trusted hosts until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0242?
CVE-1999-0242 is considered a high severity vulnerability due to the potential for remote attacks on mail files.
How do I fix CVE-1999-0242?
To fix CVE-1999-0242, ensure that the POP3 service is properly configured to restrict access and consider using alternatives if necessary.
Which systems are affected by CVE-1999-0242?
CVE-1999-0242 affects Linux systems utilizing shadow passwords, particularly those running Slackware Linux.
What type of attack does CVE-1999-0242 involve?
CVE-1999-0242 involves remote attacks that can exploit POP3 to access sensitive mail files.
Is user authentication impacted by CVE-1999-0242?
Yes, CVE-1999-0242 can compromise user authentication by allowing unauthorized access to mail files.