CVE-1999-0879: Buffer Overflow
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
WU-FTPD (BSDI BSD/OS, SCO OpenLinux Server)from your environment.Uninstall WU-FTPD from affected systems if the FTP service is not required.
- Configuration
Stop and disable the WU-FTPD (ftp) daemon on affected systems (BSDI BSD/OS and SCO OpenLinux Server) until a vendor fix is available.
WU-FTPD enabled = false - Compensating control
Block or restrict access to FTP (TCP port 21) at the network perimeter and firewall; allow access only from trusted management IPs or internal networks until the vulnerability is remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0879?
CVE-1999-0879 is considered a critical vulnerability due to the potential for remote attackers to gain root privileges.
How do I fix CVE-1999-0879?
To fix CVE-1999-0879, update WU-FTPD and any affected FTP servers to the latest patched version.
Who is affected by CVE-1999-0879?
CVE-1999-0879 affects users of WU-FTPD and related FTP servers on specific BSD and SCO OpenLinux versions.
What type of vulnerability is CVE-1999-0879?
CVE-1999-0879 is a buffer overflow vulnerability that can be exploited to execute arbitrary code.
What are the potential impacts of CVE-1999-0879?
The potential impacts of CVE-1999-0879 include unauthorized access and control over the vulnerable system with root privileges.