CVE-1999-0752: Buffer Overflow
Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable SSL/HTTPS (stop accepting SSL connections) on the server to mitigate the buffer overflow in the SSL handshake until an official fix is available.
Netscape Enterprise Server SSL/HTTPS (SSL handshake) = disabled - Compensating control
Restrict access to the server's SSL/TLS ports at the network perimeter (firewall/ACL) to trusted IP addresses only, and block or rate-limit connection attempts from untrusted networks to reduce exposure to the vulnerability.
- Operational
Monitor the server for crashes, service interruptions, and signs of denial-of-service; maintain incident response procedures to restart or restore services as needed and apply any vendor-provided patch or advisory as soon as it becomes available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0752?
CVE-1999-0752 is considered a high-severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-1999-0752?
To fix CVE-1999-0752, you should update your Netscape Enterprise Server to the latest version that addresses the buffer overflow vulnerability.
What is the impact of CVE-1999-0752?
The impact of CVE-1999-0752 is that it can lead to a denial of service, rendering the server unresponsive during the SSL handshake.
Which software is affected by CVE-1999-0752?
CVE-1999-0752 affects Netscape Enterprise Server across all versions.
When was CVE-1999-0752 disclosed?
CVE-1999-0752 was disclosed in 1999, highlighting a critical security flaw present in the software.