CVE-1999-0841: Buffer Overflow
Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SunOS/CDE mailtoolfrom your environment.Uninstall or disable the CDE mailtool binary on affected SunOS systems to eliminate the vulnerable component that can be exploited via a long MIME Content-Type.
- Compensating control
Restrict execution of the CDE mailtool binary to trusted administrators (for example, remove execute permission for non-privileged users or apply local filesystem ACLs) or otherwise prevent untrusted local users from running the binary.
- Operational
Audit affected systems for signs of local exploitation and potential root compromise. If compromise is suspected, perform incident response actions such as restoring from known-good backups, reinstalling from trusted media, and rotating any potentially exposed credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0841?
CVE-1999-0841 is considered critical due to its potential to allow local users to gain root privileges.
How do I fix CVE-1999-0841?
To fix CVE-1999-0841, it is recommended to apply patches provided by the vendor for SunOS 5.7.
Who is affected by CVE-1999-0841?
Local users on systems running SunOS 5.7 are affected by CVE-1999-0841.
What type of vulnerability is CVE-1999-0841?
CVE-1999-0841 is a buffer overflow vulnerability in the CDE mailtool.
What can an attacker do with CVE-1999-0841?
An attacker can exploit CVE-1999-0841 to execute arbitrary code with root privileges.