CVE-1999-0685: Buffer Overflow
Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the pluginspage option or stop using EMBED tags in pages opened by Netscape Communicator to avoid triggering the buffer overflow.
Netscape Communicator pluginspage option (EMBED tag handling) = disable or avoid using EMBED tags - Compensating control
Filter or strip EMBED tags from web content served to clients (for example via a web proxy, WAF, or content-filtering layer) to block attempts to exploit the EMBED-tag-related buffer overflow.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0685?
CVE-1999-0685 has a high severity rating due to the potential for remote code execution through a buffer overflow.
How do I fix CVE-1999-0685?
To fix CVE-1999-0685, upgrade Netscape Communicator to a version that is not affected by the vulnerability, such as versions later than 4.61.
What versions of Netscape Communicator are affected by CVE-1999-0685?
CVE-1999-0685 affects Netscape Communicator versions 4.5 through 4.61.
What type of attack is possible due to CVE-1999-0685?
CVE-1999-0685 allows an attacker to execute arbitrary code on a user's system through specially crafted EMBED tags.
Is CVE-1999-0685 still a relevant vulnerability today?
While CVE-1999-0685 was a significant issue at the time, it is largely irrelevant today due to the obsolescence of Netscape Communicator.