CVE-1999-0389: Buffer Overflow
Buffer overflow in the bootp server in the Debian Linux netstd package.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
debian/netstdfrom your environment.Uninstall the netstd package if BOOTP functionality is not required on the system.
- Configuration
Disable the bootp server provided by the netstd package until a patched version is available.
netstd bootp server bootp_server_enabled = false - Compensating control
Restrict or block access to the BOOTP service from untrusted networks (for example via firewall rules) until a fix is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0389?
CVE-1999-0389 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-1999-0389?
To fix CVE-1999-0389, you should upgrade to a patched version of the Debian netstd package that addresses the buffer overflow issue.
What is the impact of CVE-1999-0389?
The impact of CVE-1999-0389 includes unauthorized access and potential control over affected systems due to the buffer overflow in the bootp server.
Which Debian versions are affected by CVE-1999-0389?
CVE-1999-0389 affects Debian GNU/Linux versions 1.1, 1.2, 1.3, 1.3.1, and 2.0.
Is there any workaround for CVE-1999-0389?
There are no published workarounds for CVE-1999-0389; the recommended mitigation is to upgrade to a secure version.