CVE-1999-0302: High severity Sun SunOS vulnerability
SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SunOS/Solaris FTP clientfrom your environment.Uninstall or disable the FTP client on affected SunOS/Solaris systems if it is not required to eliminate the attack surface that allows a malicious FTP server to trigger execution of arbitrary commands.
- Compensating control
Restrict FTP client network access until a vendor fix is available: block or limit outbound FTP (TCP/21) to only trusted FTP servers via firewall rules or ACLs, and prevent connections to untrusted or public FTP servers.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0302?
CVE-1999-0302 is considered a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-1999-0302?
To fix CVE-1999-0302, ensure that your FTP client software is updated to a secure version that addresses this vulnerability.
Which systems are affected by CVE-1999-0302?
CVE-1999-0302 affects versions of SunOS 5.3, 5.5, 5.5.1, and Solaris 2.6.
What are the risks associated with CVE-1999-0302?
The risks of CVE-1999-0302 include unauthorized access and control over the system by an attacker through malicious FTP connections.
Is CVE-1999-0302 still relevant today?
While CVE-1999-0302 is an old vulnerability, it remains relevant for environments still using affected versions of SunOS or Solaris.