CVE-1999-1356: Medium severity Compaq SmartStart vulnerability
Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Compaq SmartStartto a version that resolves this vulnerability.Fixed in 4.50 - Configuration
Verify the LegalNoticeCaption and LegalNoticeText registry values on affected Windows NT systems and restore them to text that complies with your security policy if they have been modified (they may have been changed by the Compaq Integration Maintenance Utility as used in the Compaq Insight Manager agent).
Windows NT (LegalNoticeCaption / LegalNoticeText) LegalNoticeCaption, LegalNoticeText = values compliant with organisation security policy
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1356?
CVE-1999-1356 is considered a medium severity vulnerability due to potential violations of security policies regarding legal notice display.
How do I fix CVE-1999-1356?
To fix CVE-1999-1356, upgrade the Compaq Insight Manager agent to SmartStart version 4.50 or later.
What versions are affected by CVE-1999-1356?
CVE-1999-1356 affects all versions of Compaq SmartStart prior to 4.50.
What is the impact of exploiting CVE-1999-1356?
Exploitation of CVE-1999-1356 may lead to the modification of the legal notice which can violate security policies.
Is CVE-1999-1356 still relevant today?
Yes, CVE-1999-1356 remains relevant as legacy systems running affected software may still be in use.