CVE-1999-0299: Buffer Overflow
Buffer overflow in FreeBSD lpd through long DNS hostnames.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Stop the lpd service and disable it from starting automatically until an official patch or vendor fix is available.
FreeBSD lpd service_enabled = false - Compensating control
Restrict network access to the lpd service (TCP/UDP port 515) using perimeter firewalls and host-based firewalls; allow only trusted management hosts to connect.
- Operational
Inspect hosts running lpd for signs of compromise and perform incident response if suspicious activity is found; apply vendor patches or updates when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0299?
CVE-1999-0299 has a high severity rating due to the potential for remote code execution caused by the buffer overflow.
How do I fix CVE-1999-0299?
To fix CVE-1999-0299, upgrade to the latest patched version of FreeBSD that addresses this vulnerability.
What software is affected by CVE-1999-0299?
CVE-1999-0299 affects FreeBSD version 6.2-stable and prior versions.
What type of vulnerability is CVE-1999-0299?
CVE-1999-0299 is classified as a buffer overflow vulnerability.
Can CVE-1999-0299 be exploited remotely?
Yes, CVE-1999-0299 can be exploited remotely through long DNS hostnames sent to the lpd service.