CVE-1999-1435: Buffer Overflow
Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
socks5/libsocks5from your environment.Uninstall or remove the libsocks5 library (Socks5) from systems where it is not required to eliminate the vulnerable code.
- Compensating control
Until a patch is available, prevent untrusted local users from exercising the vulnerability: restrict local account access, remove execution privileges for the socks5 binaries for untrusted users, and ensure the socks5 service is not run with elevated/privileged accounts (run under a dedicated unprivileged account).
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1435?
CVE-1999-1435 has a high severity level due to the potential for local users to gain elevated privileges.
How do I fix CVE-1999-1435?
To address CVE-1999-1435, consider upgrading the libsocks5 library to a version that is not vulnerable to buffer overflow.
Who is affected by CVE-1999-1435?
CVE-1999-1435 affects users of the Nec Socks 5 library version 1.0r5.
What type of vulnerability is CVE-1999-1435?
CVE-1999-1435 is classified as a buffer overflow vulnerability.
Can CVE-1999-1435 be exploited remotely?
No, CVE-1999-1435 requires local access to exploit the buffer overflow issue.