CVE-1999-0406: Buffer Overflow
Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Digital Unix Networker nsralistfrom your environment.Uninstall or remove the nsralist program from affected Digital OpenVMS systems if it is not required.
- Compensating control
Prevent unprivileged local users from executing nsralist by restricting file permissions and access to the binary to trusted administrator accounts only; apply local host controls or ACLs to block execution by non-administrative users.
- Operational
If untrusted users had access to systems with the vulnerable nsralist, investigate for signs of local privilege escalation and perform incident response actions such as rotating root/administrator credentials and keys if compromise is suspected.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0406?
CVE-1999-0406 is considered a critical vulnerability due to its potential for local users to gain root privileges.
How do I fix CVE-1999-0406?
To fix CVE-1999-0406, update the Digital Unix Networker program to the latest version that addresses this buffer overflow.
Who is affected by CVE-1999-0406?
CVE-1999-0406 affects local users of the Digital Unix Networker program that is susceptible to buffer overflow vulnerabilities.
What type of vulnerability is CVE-1999-0406?
CVE-1999-0406 is a buffer overflow vulnerability that can result in escalation of privileges.
When was CVE-1999-0406 disclosed?
CVE-1999-0406 was disclosed in 1999.