CVE-2000-0165: Buffer Overflow
The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
ETL Delegatefrom your environment.If the ETL Delegate application proxy is not required, uninstall or disable it until a vendor patch or official remediation is available.
- Compensating control
Restrict network access to the ETL Delegate application proxy: block or limit incoming access at perimeter firewalls and internal ACLs to only trusted management IPs or place the service behind a VPN; isolate affected hosts from untrusted networks until a vendor fix is available.
- Operational
Treat hosts running the ETL Delegate as potentially compromised: perform forensic investigation, check for signs of command execution or persistence, restore from known-good backups if compromise is confirmed, and rotate any credentials, API keys, or secrets that may have been exposed prior to applying a fix.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0165?
CVE-2000-0165 has a moderate severity rating due to the potential for remote code execution.
How do I fix CVE-2000-0165?
To fix CVE-2000-0165, you should upgrade the Delegate application to the latest version that addresses the buffer overflow vulnerabilities.
What versions of Delegate are affected by CVE-2000-0165?
CVE-2000-0165 affects Delegate versions 5.9 and 6.0.
What type of attack does CVE-2000-0165 enable?
CVE-2000-0165 enables remote attackers to execute arbitrary commands on the affected system.
Is CVE-2000-0165 a common vulnerability?
CVE-2000-0165 is considered common within its context, as buffer overflow vulnerabilities were prevalent in early software releases.