CVE-1999-1517: High severity FreeBSD FreeBSD vulnerability

Published Nov 1, 1999
·
Updated

runtar in the Amanda backup system used in various UNIX operating systems executes tar with root privileges, which allows a user to overwrite or read arbitrary files by providing the target files to runtar.

Affected Software

1 affected component
FreeBSD FreeBSD=3.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove amanda/runtar from your environment.

    If runtar is not required, uninstall or disable the runtar component in the Amanda installation so it cannot be invoked by users.

  2. Configuration

    Modify runtar so it does not invoke tar with root privileges. Drop privileges or execute tar under a dedicated unprivileged account before processing user-supplied file paths so runtar cannot read or overwrite arbitrary files.

    Amanda runtar execution privileges = do not run as root; run under an unprivileged account
  3. Compensating control

    Restrict who can execute runtar to trusted administrative users only (using filesystem permissions, sudoers, or similar access controls). If immediate code changes are not possible, limit invocation of runtar and restrict which target paths are allowed by external controls until a permanent fix is applied.

Event History

Nov 1, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1517?

CVE-1999-1517 is considered a critical vulnerability due to its ability to allow unauthorized file access and execution with root privileges.

2

How do I fix CVE-1999-1517?

To fix CVE-1999-1517, update the Amanda backup system to a version that does not execute tar with root privileges.

3

Which systems are affected by CVE-1999-1517?

CVE-1999-1517 primarily affects FreeBSD 3.3 and may also impact other UNIX-based systems using the Amanda backup system.

4

What are the risks of CVE-1999-1517?

The risks associated with CVE-1999-1517 include unauthorized file modifications and data breaches due to elevated access privileges.

5

Can CVE-1999-1517 be exploited remotely?

Yes, CVE-1999-1517 can potentially be exploited remotely if proper access controls are not implemented.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203