CVE-1999-1471: Buffer Overflow

Published Jan 1, 1989
·
Updated

Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.

Affected Software

2 affected components
BSD BSD=4.2
BSD BSD=4.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Configure or harden the passwd/account management process so that shell and GECOS fields are validated and limited to a reasonable maximum length; where built-in configuration is not available, restrict who may set or change these fields to administrators only.

    BSD passwd shell/GECOS field length validation = enforce maximum length / disallow overly long values
  2. Compensating control

    Restrict account creation and modification and limit local login access to trusted administrators and accounts only (host-based access controls, local account policy, or similar) until an upstream fix is available to prevent unprivileged local users from exploiting the passwd vulnerability to gain root.

  3. Operational

    Monitor BSD vendor/security advisories for a patch or fixed release for the passwd vulnerability; when a vendor-supplied fix is published, test and apply it promptly. In the meantime, audit passwd usage and account changes for suspicious activity and investigate any potential compromises.

Event History

Jan 1, 1989
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1471?

CVE-1999-1471 has a high severity due to its potential to allow local users to gain root privileges.

2

How do I fix CVE-1999-1471?

To fix CVE-1999-1471, it is recommended to upgrade to a newer version of the BSD operating system that does not have this vulnerability.

3

What types of systems are affected by CVE-1999-1471?

CVE-1999-1471 affects BSD based operating systems, specifically versions 4.2 and 4.3.

4

Can CVE-1999-1471 be exploited remotely?

CVE-1999-1471 cannot be exploited remotely as it requires local user access to the system.

5

What is the impact of CVE-1999-1471 on my system?

The impact of CVE-1999-1471 can result in unauthorized root access, compromising system integrity and security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203