First published: Fri Dec 31 1999(Updated: )
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Debian Linux | =4.0 | |
Red Hat Linux | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1330 is classified as a moderate severity vulnerability due to the potential for buffer overflow attacks.
To fix CVE-1999-1330, you should update the db library to the latest version that implements snprintf properly.
CVE-1999-1330 affects db library version 1.85.4, particularly on Debian Linux 4.0 and Red Hat Linux 4.2.
The potential impact of CVE-1999-1330 includes the ability for attackers to execute arbitrary code through buffer overflows.
CVE-1999-1330 is considered a historical vulnerability, but if legacy systems using affected software are still in use, they can remain at risk.