CVE-1999-0853: Buffer Overflow
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable HTTP Basic Authentication on the affected servers to prevent exploitation via the HTTP Basic Authentication procedure.
Netscape Enterprise Server / Netscape FastTrack Server HTTP Basic Authentication = disabled - Compensating control
Restrict remote access to the affected servers (Netscape Enterprise Server and Netscape FastTrack Server) to trusted IP ranges or internal networks using firewall rules or ACLs to mitigate the risk of remote attackers exploiting the vulnerability.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0853?
CVE-1999-0853 is considered a high severity vulnerability due to its potential to allow remote attackers to gain unauthorized privileges.
How do I fix CVE-1999-0853?
To fix CVE-1999-0853, it is recommended to upgrade to a patched version of Netscape Enterprise Server or Netscape FastTrack Server.
Which versions of software are affected by CVE-1999-0853?
CVE-1999-0853 affects Netscape Enterprise Server versions 3.5.1 and 3.6, as well as Netscape FastTrack Server version 3.01.
What kind of attack does CVE-1999-0853 involve?
CVE-1999-0853 involves a buffer overflow attack that can be exploited through the HTTP Basic Authentication process.
Can CVE-1999-0853 be exploited remotely?
Yes, CVE-1999-0853 can be exploited remotely, allowing attackers to potentially escalate their privileges.