CVE-1999-0789: Buffer Overflow
Buffer overflow in AIX ftpd in the libc library.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
AIX ftpdfrom your environment.Uninstall ftpd from systems where the FTP service is not required.
- Configuration
Disable the ftpd service on affected IBM AIX systems until a vendor patch is available.
AIX ftpd service_enabled = false - Compensating control
Block or restrict access to FTP (TCP port 21) using perimeter and host-based firewalls or access control lists to prevent exploitation of the vulnerable ftpd.
- Operational
Inventory AIX hosts to identify systems running ftpd, monitor logs for signs of exploitation, and apply any vendor-supplied fixes or patches when they are released.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0789?
CVE-1999-0789 has a high severity rating due to the potential for remote code execution through a buffer overflow in the FTP daemon.
How do I fix CVE-1999-0789?
To fix CVE-1999-0789, users should apply the appropriate patches provided by IBM for affected versions of AIX.
Which versions of AIX are affected by CVE-1999-0789?
CVE-1999-0789 affects IBM AIX versions 4.3, 4.3.1, and 4.3.2.
What type of vulnerability is CVE-1999-0789?
CVE-1999-0789 is classified as a buffer overflow vulnerability in the ftpd service of the AIX operating system.
Is CVE-1999-0789 a local or remote vulnerability?
CVE-1999-0789 is a remote vulnerability, allowing attackers to exploit it over the network.