CVE-1999-0920: Buffer Overflow
Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
University of Washington POP2Dfrom your environment.Uninstall the pop-2d POP daemon if POP service is not required.
- Remove
Remove
University of Washington UW-IMAPfrom your environment.Uninstall the UW-IMAP package or remove the pop-2d component if POP service is not required.
- Configuration
Stop and disable the pop-2d POP daemon/service to prevent remote exploitation via the FOLD command.
University of Washington POP2D (pop-2d) service_enabled = false - Compensating control
Block or restrict network access to the POP service (TCP port 110) at the perimeter firewall or via host-based firewall rules; allow access only from trusted hosts if POP is required.
- Operational
Monitor systems and logs for suspicious activity related to pop-2d and apply vendor fixes or patches when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0920?
CVE-1999-0920 is considered to have a high severity due to the potential for remote privilege escalation.
How do I fix CVE-1999-0920?
To fix CVE-1999-0920, upgrade to a patched version of the IMAP package or the POP2D daemon provided by the University of Washington.
What platforms are affected by CVE-1999-0920?
CVE-1999-0920 affects the University of Washington IMAP version 4.4 and the POP2D daemon.
What can attackers do with CVE-1999-0920?
Attackers exploiting CVE-1999-0920 can gain elevated privileges on the affected system via the FOLD command.
Is CVE-1999-0920 still a threat today?
While CVE-1999-0920 is an older vulnerability, it poses a threat to any unpatched systems still running affected software.