CVE-1999-0710: High severity redhat Linux vulnerability
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
squid (Red Hat Linux 5.2, 6.0)from your environment.Uninstall the Squid package if it is not required.
- Configuration
Remove cachemgr.cgi from publicly accessible web directories or reconfigure the web server to deny external access (for example, allow only localhost or the management subnet) so cachemgr.cgi cannot be used as an intermediary.
Squid (cachemgr.cgi) install_location/access = not in public web directory; deny external access - Compensating control
Restrict network access to the web server hosting cachemgr.cgi using firewall rules/ACLs/WAF so only trusted hosts or internal management networks can reach the CGI.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0710?
CVE-1999-0710 is considered a high-severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-1999-0710?
To fix CVE-1999-0710, remove or restrict access to the cachemgr.cgi file and ensure it is not publicly accessible.
Which versions of Red Hat Linux are affected by CVE-1999-0710?
CVE-1999-0710 affects Red Hat Linux versions 5.2 and 6.0.
What type of attack does CVE-1999-0710 allow?
CVE-1999-0710 allows remote attackers to use the cachemgr.cgi script as an intermediary to connect to other systems.
Is CVE-1999-0710 still relevant today?
While CVE-1999-0710 pertains to older software versions, it is still relevant for environments that continue to use those versions.