CVE-1999-1237: Buffer Overflow

Published Jun 6, 1999
·
Updated

Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.

Affected Software

1 affected component
Apache HTTP Server

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Apache::AuthenSmb from your environment.

    Uninstall or remove the Apache::AuthenSmb module from the server if it is not required. Remove any LoadModule lines and related authentication configuration to prevent use of the vulnerable SMB authentication integration.

  2. Remove

    Remove smbvalid/smbval from your environment.

    Uninstall the smbvalid/smbval SMB authentication library from systems using it (or replace it with a non-vulnerable alternative) to eliminate the vulnerable code paths used by Apache::AuthenSmb and other modules.

  3. Configuration

    Disable SMB-based authentication in Apache configuration (remove or comment out configuration that invokes Apache::AuthenSmb and prevent the module from being loaded) until a fixed version or patch is available.

    Apache::AuthenSmb enabled = false
  4. Compensating control

    Restrict network access to systems and services that rely on smbvalid/smbval or Apache::AuthenSmb (limit to trusted hosts/networks via firewall, ACLs or other network controls) to reduce exposure to remote attackers until the vulnerability is remediated.

Event History

Jun 6, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityWeaknessAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1237?

CVE-1999-1237 has a high severity due to the potential for remote command execution.

2

How do I fix CVE-1999-1237?

To fix CVE-1999-1237, update the affected software to a version that addresses the buffer overflow vulnerabilities.

3

Which software is affected by CVE-1999-1237?

CVE-1999-1237 affects the Apache HTTP Server and potentially other modules using the smbvalid/smbval SMB authentication library.

4

What types of attacks can exploit CVE-1999-1237?

CVE-1999-1237 can be exploited through attacks that supply overly long usernames or passwords during authentication.

5

Are there any known exploits for CVE-1999-1237?

Yes, there are known exploits for CVE-1999-1237 that leverage the buffer overflow conditions to execute arbitrary commands.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203