CVE-1999-0840: Buffer Overflow
Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
CDE dtmail and dtmailpr (SunOS)from your environment.Uninstall or remove the vulnerable dtmail and dtmailpr binaries from affected SunOS systems if they are not required.
- Compensating control
Restrict access to the dtmail and dtmailpr binaries pending a vendor fix: remove execute permission for non‑administrative users or limit execution to trusted administrative accounts (adjust file ownership/permissions or use local access controls).
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0840?
CVE-1999-0840 is considered a high severity vulnerability due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-1999-0840?
To address CVE-1999-0840, you should upgrade to a version of the affected software that is not vulnerable.
Who is affected by CVE-1999-0840?
CVE-1999-0840 affects local users of SunOS 5.7 specifically using the dtmail and dtmailpr programs.
What type of vulnerability is CVE-1999-0840?
CVE-1999-0840 is classified as a buffer overflow vulnerability.
Can CVE-1999-0840 be exploited remotely?
CVE-1999-0840 cannot be exploited remotely as it requires local access to the system.