CVE-1999-0303: Buffer Overflow
Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
BNU UUCP daemon (uucpd)from your environment.Uninstall or remove the uucpd package/component on systems where UUCP functionality is not required.
- Configuration
Disable the uucpd service/daemon on affected systems until a vendor patch is available to eliminate the buffer overflow via long hostnames.
BNU UUCP daemon (uucpd) enabled = false - Compensating control
Block UUCP/uucpd network traffic at the network perimeter and host-based firewalls (restrict access to UUCP services to trusted management hosts only) to prevent remote exploitation via long hostnames.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0303?
CVE-1999-0303 is classified as a high-severity vulnerability due to the potential for buffer overflow, which can lead to arbitrary code execution.
How do I fix CVE-1999-0303?
To fix CVE-1999-0303, you should upgrade to an unaffected version of the software that the BNU UUCP daemon runs on, or apply a security patch provided by the vendor.
What systems are affected by CVE-1999-0303?
CVE-1999-0303 affects various versions of SunOS, Solaris, NetBSD, and OpenBSD systems that have the BNU UUCP daemon (uucpd) installed.
What type of vulnerability is CVE-1999-0303?
CVE-1999-0303 is a buffer overflow vulnerability that can be exploited through long hostname inputs to the BNU UUCP daemon.
Can CVE-1999-0303 be exploited remotely?
Yes, CVE-1999-0303 can be exploited remotely if an attacker can send specially crafted requests to the affected BNU UUCP daemon.