CVE-1999-1385: Buffer Overflow
Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
FreeBSD ppp programfrom your environment.Uninstall or remove the ppp program from systems where it is not required to eliminate the vulnerable component.
- Compensating control
Restrict local access to and execution of the ppp binary until a patch is available (e.g., tighten filesystem permissions, apply ACLs, or limit which accounts can run ppp).
- Operational
Audit systems for signs of local privilege escalation and review local accounts. If compromise is suspected, perform incident response actions such as containment, credential rotation, and restore from trusted backups.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1385?
CVE-1999-1385 has a high severity rating due to the potential for local users to gain elevated privileges.
How do I fix CVE-1999-1385?
To fix CVE-1999-1385, upgrade to a version of FreeBSD later than 2.1.6.1.
Who is affected by CVE-1999-1385?
CVE-1999-1385 affects local users of FreeBSD versions 2.1 and earlier.
What systems are vulnerable to CVE-1999-1385?
Systems running FreeBSD 2.1 or earlier are vulnerable to CVE-1999-1385.
What kind of vulnerability is CVE-1999-1385?
CVE-1999-1385 is a buffer overflow vulnerability in the ppp program.