CVE-1999-0318: Buffer Overflow
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
xmcd 2.0p12from your environment.Uninstall xmcd 2.0p12 from affected systems if the component is not required.
- Configuration
Stop and disable the xmcd daemon/service where present to prevent exploitation via environment variables.
xmcd enabled = false - Compensating control
Restrict execution of the xmcd binary to trusted administrators by adjusting file permissions and local access controls so unprivileged local users cannot run it.
- Operational
Inventory and scan systems (HPE HP-UX, IBM AIX, Oracle Solaris and ZFS, Red Hat Linux, SunOS) for the presence of xmcd 2.0p12 and remediate identified instances (remove/disable) as appropriate.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0318?
CVE-1999-0318 is classified as a moderate severity vulnerability due to the potential for local users to gain unauthorized access.
How do I fix CVE-1999-0318?
To fix CVE-1999-0318, update the affected application to a version that mitigates the buffer overflow issue.
What systems are affected by CVE-1999-0318?
CVE-1999-0318 affects various versions of IBM AIX, SunOS, HP-UX, and Red Hat Linux.
Who is vulnerable to CVE-1999-0318?
Local users on systems running vulnerable software versions are at risk with CVE-1999-0318.
What type of vulnerability is CVE-1999-0318?
CVE-1999-0318 is a buffer overflow vulnerability that can be exploited through an environmental variable.