CVE-1999-1226: Low severity Netscape Communicator vulnerability
Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Netscape Communicatorfrom your environment.Uninstall or stop using Netscape Communicator (versions 4.7 and earlier), which are vulnerable to remote denial-of-service and possible code execution via a long certificate key.
- Compensating control
Restrict network exposure of systems running Netscape Communicator 4.7 or earlier (for example, block or limit incoming access that could submit certificates at the firewall/ACL) to reduce the risk of remote attackers sending crafted long certificate keys.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1226?
CVE-1999-1226 is classified as a high severity vulnerability due to its potential to cause a denial of service and execute arbitrary commands.
How do I fix CVE-1999-1226?
The best way to fix CVE-1999-1226 is to upgrade to a later version of Netscape Communicator that addresses this vulnerability.
What type of attacks can exploit CVE-1999-1226?
CVE-1999-1226 can be exploited through remote attacks that send long certificate keys to the vulnerable software.
Which versions of Netscape Communicator are affected by CVE-1999-1226?
CVE-1999-1226 affects Netscape Communicator version 4.7 and earlier.
What are the consequences of CVE-1999-1226?
Exploiting CVE-1999-1226 can lead to a denial of service and potentially allow an attacker to execute arbitrary commands.