CVE-1999-1282: Medium severity RealNetworks Realsystem G2 Server vulnerability
RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
RealNetworks RealSystem G2 Serverfrom your environment.If the RealSystem G2 Server is not required, uninstall or remove the software to eliminate the vulnerable component.
- Configuration
Change the configuration file ownership and permissions so the administrator password is not world-readable. Restrict ownership to an administrative account and remove world-read access (for example, adjust permissions or apply host ACLs; e.g., chmod 640 or equivalent).
RealNetworks RealSystem G2 Server configuration file file permissions (world-readable) = remove world-readable permission - Compensating control
Restrict local access to affected hosts: disable or remove unneeded local accounts, apply host-based access controls or filesystem ACLs to prevent unprivileged users from reading configuration files, and limit interactive logins to trusted administrators.
- Operational
Rotate the administrator password and any other credentials that may have been stored in the file. Assume possible exposure and update credentials after securing the file.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1282?
CVE-1999-1282 is considered a high severity vulnerability due to the exposure of the administrator password in cleartext.
How do I fix CVE-1999-1282?
To fix CVE-1999-1282, you should change the configuration file permissions to restrict access and ensure that passwords are stored securely, not in cleartext.
Who is affected by CVE-1999-1282?
Any local users with access to the configuration file of the RealSystem G2 server are affected by CVE-1999-1282.
What systems are vulnerable to CVE-1999-1282?
Realnetworks Realsystem G2 Server installations are vulnerable to CVE-1999-1282 if they store the administrator password in a world-readable configuration file.
What can an attacker do with CVE-1999-1282?
An attacker exploiting CVE-1999-1282 can gain unauthorized privileges on the system by accessing the cleartext administrator password.