CVE-1999-0978: High severity Debian Debian Linux vulnerability
htdig allows remote attackers to execute commands via filenames with shell metacharacters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
debian/htdigfrom your environment.Uninstall the htdig package from affected systems if it is not required.
- Compensating control
Restrict or block network access to the htdig service (for example with firewall rules, ACLs, or by configuring the service to bind only to localhost) to prevent remote exploitation until an official fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0978?
CVE-1999-0978 is considered to have a critical severity due to the potential for remote command execution.
How do I fix CVE-1999-0978?
To fix CVE-1999-0978, update to a patched version of htdig that does not allow shell metacharacters in filenames.
Which software is affected by CVE-1999-0978?
HTDig on Debian Linux 2.1 is specifically affected by CVE-1999-0978.
Can CVE-1999-0978 be exploited remotely?
Yes, CVE-1999-0978 can be exploited remotely, allowing attackers to execute arbitrary commands.
What are the consequences of exploiting CVE-1999-0978?
Exploiting CVE-1999-0978 can lead to total system compromise and unauthorized access to sensitive information.