CVE-1999-1059: Critical severity att svr4 vulnerability
Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
AT&T TCP/IP 4.0 - rexec daemon (rexecd)from your environment.If the rexec service is not required, uninstall or remove the rexecd binary from affected systems.
- Configuration
Stop and disable the rexec daemon (rexecd) on affected SVR4 systems to prevent remote command execution.
AT&T TCP/IP 4.0 (SVR4) - rexec daemon (rexecd) rexecd_enabled = false - Compensating control
Block or restrict network access to the rexec service (rexecd) at network perimeter devices/firewalls or isolate affected hosts to prevent remote access until the vulnerability is addressed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1059?
CVE-1999-1059 is classified as a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary commands.
How do I fix CVE-1999-1059?
To fix CVE-1999-1059, it is recommended to disable the rexec daemon or apply patches provided by the vendor.
What systems are affected by CVE-1999-1059?
CVE-1999-1059 affects AT&T TCP/IP 4.0 for various SVR4 systems.
Can CVE-1999-1059 be exploited remotely?
Yes, CVE-1999-1059 can be exploited remotely by attackers to execute commands without authentication.
Is there a workaround for CVE-1999-1059 if I cannot disable the rexec daemon?
If disabling the rexec daemon is not possible, consider restricting access through firewall rules or network segmentation.