CVE-1999-1506: High severity Sun SunOS vulnerability
Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SMI Sendmail 4.0 and earlier (on SunOS up to 4.0.3)from your environment.Uninstall SMI Sendmail or disable the sendmail service on affected SunOS systems (SunOS up to 4.0.3) until a vendor-supplied fix is available.
- Compensating control
Block or restrict incoming SMTP/sendmail network access (e.g., TCP port 25) to affected SunOS hosts at the network perimeter or host-based firewall to prevent remote exploitation until patched or removed.
- Operational
Inspect user bin (e.g., /usr/bin) on affected systems for unauthorized modifications or access that may indicate exploitation, and investigate any suspicious findings.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1506?
CVE-1999-1506 has a high severity level due to its potential for remote attacks.
How do I fix CVE-1999-1506?
To fix CVE-1999-1506, upgrade to a patched version of Sendmail or implement appropriate security measures.
Which software versions are affected by CVE-1999-1506?
CVE-1999-1506 affects Sendmail 4.0 and earlier on SunOS versions up to 4.0.3.
Can CVE-1999-1506 be exploited remotely?
Yes, CVE-1999-1506 allows remote attackers to access the user bin.
What kind of systems are vulnerable to CVE-1999-1506?
Systems running Sendmail 4.0 or earlier on SunOS 3.5 to 4.0.3 are vulnerable to CVE-1999-1506.