CVE-1999-0284: Buffer Overflow

Published Jan 1, 1998
·
Updated

Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.

Affected Software

3 affected components
IBM Lotus Domino Mail Server
Microsoft Exchange Server=4.0
Microsoft Exchange Server=5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Configure the mail servers to reject malformed HELO commands, enforce strict input validation on HELO, and restrict acceptance of SMTP from untrusted networks or relays until a vendor fix is available.

    Mail servers (IBM Domino, Microsoft Exchange Server) HELO handling / SMTP acceptance from untrusted networks = reject malformed HELOs; restrict SMTP acceptance to trusted peers
  2. Compensating control

    Restrict inbound SMTP (TCP port 25) access to IBM Domino, Microsoft Exchange Server, Ipswitch and MDaemon hosts at the network perimeter to trusted IPs/networks only (block or allow-list source IPs).

  3. Compensating control

    Deploy or enable IDS/IPS/WAF signatures to detect and block exploit attempts targeting the SMTP HELO command (malformed HELOs / buffer overflow attempts) against mail servers (IBM Domino, Microsoft Exchange Server, Ipswitch, MDaemon).

  4. Compensating control

    Isolate affected mail servers from untrusted networks (place in a segregated VLAN or apply ACLs) until a vendor patch or workaround is available to prevent denial-of-service via SMTP HELO buffer overflow.

  5. Operational

    Monitor mail server logs and network telemetry for crashes, excessive SMTP connections, or repeated malformed HELO commands and perform incident response (containment and forensic capture) if exploitation is observed.

Event History

Jan 1, 1998
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0284?

CVE-1999-0284 is classified as a denial of service vulnerability affecting multiple NT mail servers.

2

How do I fix CVE-1999-0284?

To mitigate CVE-1999-0284, update your mail server software to the latest version that addresses this vulnerability.

3

Which software is affected by CVE-1999-0284?

CVE-1999-0284 affects NT mail servers, including IBM Lotus Domino Mail Server and Microsoft Exchange Server versions 4.0 and 5.0.

4

What type of vulnerability is CVE-1999-0284?

CVE-1999-0284 is a buffer overflow vulnerability that leads to denial of service.

5

Can CVE-1999-0284 be exploited remotely?

Yes, CVE-1999-0284 can be exploited remotely through the SMTP HELO command.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203