CVE-1999-1106: Buffer Overflow
Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (accountname) command line argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
kppp (KDE Beta 3)from your environment.Uninstall kppp from affected systems if it is not required. This removes the vulnerable binary until a vendor-supplied fix is available.
- Compensating control
Prevent untrusted local users from executing kppp or logging into affected systems. Restrict local account access (e.g., via local user ACLs, sudoers restrictions, or removing execute permission for non-administrative users) until a patch is available.
- Operational
Inventory and scan systems for the presence of kppp (KDE Beta 3). Disable or remove the package and do not run kppp until an official fix or updated package is provided by the vendor.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1106?
CVE-1999-1106 has been classified as a high severity vulnerability due to the potential for local users to gain root access.
How do I fix CVE-1999-1106?
To fix CVE-1999-1106, it is recommended to update KDE to a version that has patched this buffer overflow vulnerability.
Who is affected by CVE-1999-1106?
CVE-1999-1106 affects local users of KDE that utilize the kppp application.
What type of vulnerability is CVE-1999-1106?
CVE-1999-1106 is a buffer overflow vulnerability that can be exploited via command line arguments.
Can CVE-1999-1106 be exploited remotely?
No, CVE-1999-1106 is a local exploit and requires access to the system to be executed.