CVE-1999-0478: Medium severity Sendmail Sendmail vulnerability
Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Prevent sendmail from accepting external connections until a vendor fix is available. For example, bind the MTA to the loopback interface or add access rules in sendmail configuration (sendmail.cf/hosts_access) to only allow trusted hosts to connect.
Sendmail (HP-UX) accepting connections = disabled or restricted to localhost/trusted hosts - Compensating control
Mitigate the denial-of-service by restricting or rate-limiting inbound SMTP (TCP/25) connections at the network perimeter or host-based firewall. Allow only trusted IP ranges to reach the mail host and/or apply connection-rate limits until an official patch or update is provided.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0478?
CVE-1999-0478 is classified as a denial of service vulnerability.
How do I fix CVE-1999-0478?
To fix CVE-1999-0478, update your Sendmail software to a version later than 8.9.2.
What software is affected by CVE-1999-0478?
CVE-1999-0478 affects Sendmail versions up to and including 8.9.2.
What type of attack does CVE-1999-0478 involve?
CVE-1999-0478 involves an attack that results in denial of service by exploiting connection acceptance issues.
Is CVE-1999-0478 still relevant today?
CVE-1999-0478 is largely considered obsolete, but organizations using affected versions should still apply patches due to potential risks.