CVE-1999-1098: Medium severity BSD BSD vulnerability
Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
BSD Telnet clientfrom your environment.Uninstall or disable the BSD Telnet client if it is not required to prevent use of the vulnerable client.
- Configuration
Disable Kerberos 4 authentication in the BSD Telnet client to mitigate the vulnerability that allows session decryption via sniffing.
BSD Telnet client Kerberos 4 authentication = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1098?
CVE-1999-1098 has a high severity level as it allows remote attackers to decrypt user sessions.
How do I fix CVE-1999-1098?
To mitigate CVE-1999-1098, upgrade to a version of the BSD Telnet client that does not have this vulnerability.
Who is affected by CVE-1999-1098?
The BSD Telnet client users who utilize encryption and Kerberos 4 authentication are affected by CVE-1999-1098.
What type of attack is associated with CVE-1999-1098?
CVE-1999-1098 is associated with a sniffing attack where remote attackers can capture and decrypt session data.
When was CVE-1999-1098 discovered?
CVE-1999-1098 was discovered in 1999 and affects older implementations of the BSD Telnet client.