CVE-1999-0856: Medium severity Slackware Slackware Linux vulnerability
login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Modify or patch the login program so that it does not report an 'encryption error' for locked or non-existent accounts. Ensure authentication failures for locked, non-existent, and invalid accounts produce an indistinguishable, generic error message.
login (Slackware 7.0) authentication error messaging = do not disclose encryption error; return generic authentication failure for locked/non-existent accounts - Compensating control
Restrict remote access to authentication services: block or limit access to login/authentication ports with firewall rules or require access via VPN/trusted networks to reduce exposure to remote enumeration.
- Operational
Monitor authentication logs for repeated 'encryption error' messages or other indicators of user-enumeration probing and investigate/alert on suspicious activity until the login behavior is corrected.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0856?
CVE-1999-0856 has a moderate severity level as it allows remote attackers to identify valid users.
How do I fix CVE-1999-0856?
To mitigate CVE-1999-0856, consider updating to a later version of Slackware that does not have this vulnerability.
What is the impact of CVE-1999-0856 on system security?
CVE-1999-0856 can lead to information disclosure by revealing valid usernames to attackers.
Which systems are affected by CVE-1999-0856?
CVE-1999-0856 specifically affects Slackware Linux version 7.0.
Can CVE-1999-0856 be exploited remotely?
Yes, CVE-1999-0856 can be exploited remotely by attackers trying to verify user accounts.