CVE-1999-0823: Buffer Overflow
Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
FreeBSD xmindpathfrom your environment.If xmindpath is not required, remove or uninstall the xmindpath binary from systems to eliminate exposure until a patch is provided.
- Configuration
Prevent invocation of xmindpath with the -f argument until a vendor patch is available (e.g., update local scripts, wrappers or sudoers to block use of -f).
FreeBSD xmindpath -f argument usage = disabled - Compensating control
Restrict execution of the xmindpath binary to trusted administrators only (remove execute permission for unprivileged users and/or apply filesystem ACLs) until an official fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0823?
CVE-1999-0823 is classified as a high-severity vulnerability due to its ability to allow local users to gain elevated privileges.
How do I fix CVE-1999-0823?
To fix CVE-1999-0823, update your FreeBSD system to the latest version that addresses this buffer overflow vulnerability.
Who is affected by CVE-1999-0823?
CVE-1999-0823 affects local users running FreeBSD version 3.3.
What type of vulnerability is CVE-1999-0823?
CVE-1999-0823 is categorized as a buffer overflow vulnerability.
Can CVE-1999-0823 be exploited remotely?
CVE-1999-0823 cannot be exploited remotely; it requires local access to the system.