CVE-1999-0745: Buffer Overflow
Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
pdnsd (Source Code Browser Program Database Name Server Daemon)from your environment.Uninstall pdnsd from systems where the daemon is not required.
- Configuration
Stop and disable the pdnsd daemon on affected IBM AIX systems until a vendor patch is available.
pdnsd (Source Code Browser Program Database Name Server Daemon) service_enabled = false - Compensating control
Restrict network access to the pdnsd service (e.g., block or limit its listening port with firewall rules or ACLs) so only trusted hosts can reach it until a patch is applied.
- Operational
Monitor affected systems for signs of exploitation and apply vendor-supplied updates from IBM when they become available; investigate any indicators of compromise and rotate credentials if a breach is suspected.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0745?
CVE-1999-0745 is classified as a high-severity vulnerability due to the potential for remote code execution through buffer overflow.
How do I fix CVE-1999-0745?
To mitigate CVE-1999-0745, upgrading to a patched version of the affected IBM AIX or applying available security patches is recommended.
What versions of IBM AIX are affected by CVE-1999-0745?
CVE-1999-0745 affects IBM AIX versions 2.2.1, 3.1, 3.2, 3.2.4, and 3.2.5.
What type of vulnerability is CVE-1999-0745?
CVE-1999-0745 is a buffer overflow vulnerability in the Source Code Browser Program Database Name Server Daemon.
Can CVE-1999-0745 be exploited remotely?
Yes, CVE-1999-0745 can potentially be exploited remotely due to its buffer overflow nature.