First published: Tue Jul 16 1996(Updated: )
A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | <=2.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1301 is rated as a critical vulnerability due to the potential for arbitrary code execution.
To fix CVE-1999-1301, upgrade to FreeBSD version 2.1.6 or later where the vulnerability has been addressed.
CVE-1999-1301 is caused by a design flaw in the Z-Modem protocol implementation in FreeBSD.
CVE-1999-1301 affects FreeBSD versions prior to 2.1.5, particularly the rzsz module.
Yes, CVE-1999-1301 can be exploited remotely by sending a specially crafted file to execute arbitrary programs on the client.