CVE-1999-1333: High severity redhat Linux vulnerability
automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
ncftpfrom your environment.Uninstall or remove the ncftp FTP client from systems where it is not required, particularly on Red Hat Linux 5.0 and earlier.
- Configuration
Disable the automatic download option in the ncftp client configuration or avoid using the automatic download feature to prevent filenames with shell metacharacters from being executed.
ncftp (Red Hat Linux 5.0 and earlier) automatic download option = disabled - Compensating control
Restrict FTP access to trusted hosts and networks using firewall rules or ACLs to prevent connections to untrusted FTP servers that could exploit the automatic-download behavior.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1333?
CVE-1999-1333 is considered a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-1999-1333?
To fix CVE-1999-1333, upgrade to a later version of ncftp that is not vulnerable to this exploitation.
What systems are affected by CVE-1999-1333?
CVE-1999-1333 affects the ncftp 2.4.2 FTP client on Red Hat Linux 5.0 and earlier versions.
What does CVE-1999-1333 allow attackers to do?
CVE-1999-1333 allows remote attackers to execute arbitrary commands through crafted file names using shell metacharacters.
Is CVE-1999-1333 still a relevant threat today?
While CVE-1999-1333 is an older vulnerability, it is relevant for legacy systems still running vulnerable software.