CVE-1999-1512: Critical severity Amavis virus scanner vulnerability
The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
AMaViSfrom your environment.Uninstall or disable AMaViS on exposed systems until a fixed release is available or a safe mitigation is applied.
- Compensating control
At the mail gateway/MTA, filter or sanitize incoming messages to reject or remove shell metacharacters from the Reply-To header (i.e., prevent messages containing shell metacharacters from being passed to AMaViS). Alternatively restrict which systems can deliver mail to the AMaViS host via firewall/ACLs.
- Operational
If AMaViS was running on a system that may have processed untrusted mail, assume possible root compromise: perform forensic investigation, rebuild affected hosts from known-good media, and rotate any credentials or keys that may have been exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1512?
CVE-1999-1512 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary commands as root.
How do I fix CVE-1999-1512?
To fix CVE-1999-1512, upgrade AMaViS virus scanner to version 0.2.0-pre5 or later.
What type of attack does CVE-1999-1512 enable?
CVE-1999-1512 enables remote code execution attacks via specially crafted email messages.
What versions of AMaViS are affected by CVE-1999-1512?
AMaViS virus scanner versions up to and including 0.2.0-pre4 are affected by CVE-1999-1512.
What mitigation strategies can be implemented against CVE-1999-1512?
In addition to upgrading, disabling features that allow arbitrary command execution from email can help mitigate CVE-1999-1512.