CVE-1999-1111: Buffer Overflow
Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
StackGuardto a version that resolves this vulnerability.Fixed in 1.21
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1111?
CVE-1999-1111 is considered a high severity vulnerability due to its potential for exploiting the stack's security mechanisms.
How do I fix CVE-1999-1111?
To fix CVE-1999-1111, update StackGuard to version 1.21 or later.
What types of attacks can exploit CVE-1999-1111?
CVE-1999-1111 can be exploited through non-linear attack methods that modify pointers to return addresses directly.
What systems are affected by CVE-1999-1111?
CVE-1999-1111 affects versions of StackGuard prior to 1.21.
Can CVE-1999-1111 lead to remote code execution?
Yes, the vulnerability in CVE-1999-1111 can potentially lead to remote code execution by bypassing security mechanisms.