CVE-1999-1189: Buffer Overflow
Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Netscape Communicatorfrom your environment.Uninstall or discontinue use of Netscape Communicator 4.7 on Windows 95 and Windows 98 until a vendor-provided fix is available.
- Remove
Remove
Netscape Navigatorfrom your environment.Uninstall or discontinue use of Netscape Navigator 4.7 on Windows 95 and Windows 98 until a vendor-provided fix is available.
- Compensating control
On perimeter devices (firewall/proxy/WAF), block or sanitize HTTP requests containing excessively long query strings (long argument after '?'), particularly for URLs ending in .asp, .cgi, .html, or .pl, to prevent exploitation of the buffer overflow.
- Operational
Avoid browsing untrusted sites from affected hosts and monitor vendor advisories for a patch; apply the vendor fix as soon as it is released.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1189?
CVE-1999-1189 is considered to have a high severity due to its potential to cause denial of service and execution of arbitrary commands.
How do I fix CVE-1999-1189?
To fix CVE-1999-1189, upgrade to a newer version of Netscape Navigator or Communicator that does not have this vulnerability.
What products are affected by CVE-1999-1189?
CVE-1999-1189 affects Netscape Navigator and Netscape Communicator version 4.7 for Windows 95 and Windows 98.
Can CVE-1999-1189 be exploited remotely?
Yes, CVE-1999-1189 can be exploited remotely through crafted URLs with long arguments.
What types of files are associated with CVE-1999-1189 vulnerabilities?
CVE-1999-1189 vulnerabilities are associated with URLs referencing .asp, .cgi, .html, or .pl files.