CVE-1999-1282: Medium severity RealNetworks Realsystem G2 Server vulnerability

Published Dec 10, 1998
·
Updated

RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.

Affected Software

1 affected component
RealNetworks Realsystem G2 Server

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove RealNetworks RealSystem G2 Server from your environment.

    If the RealSystem G2 Server is not required, uninstall or remove the software to eliminate the vulnerable component.

  2. Configuration

    Change the configuration file ownership and permissions so the administrator password is not world-readable. Restrict ownership to an administrative account and remove world-read access (for example, adjust permissions or apply host ACLs; e.g., chmod 640 or equivalent).

    RealNetworks RealSystem G2 Server configuration file file permissions (world-readable) = remove world-readable permission
  3. Compensating control

    Restrict local access to affected hosts: disable or remove unneeded local accounts, apply host-based access controls or filesystem ACLs to prevent unprivileged users from reading configuration files, and limit interactive logins to trusted administrators.

  4. Operational

    Rotate the administrator password and any other credentials that may have been stored in the file. Assume possible exposure and update credentials after securing the file.

Event History

Dec 10, 1998
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1282?

CVE-1999-1282 is considered a high severity vulnerability due to the exposure of the administrator password in cleartext.

2

How do I fix CVE-1999-1282?

To fix CVE-1999-1282, you should change the configuration file permissions to restrict access and ensure that passwords are stored securely, not in cleartext.

3

Who is affected by CVE-1999-1282?

Any local users with access to the configuration file of the RealSystem G2 server are affected by CVE-1999-1282.

4

What systems are vulnerable to CVE-1999-1282?

Realnetworks Realsystem G2 Server installations are vulnerable to CVE-1999-1282 if they store the administrator password in a world-readable configuration file.

5

What can an attacker do with CVE-1999-1282?

An attacker exploiting CVE-1999-1282 can gain unauthorized privileges on the system by accessing the cleartext administrator password.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203