CVE-2000-0472: Buffer Overflow
Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
ISC INN (innd)from your environment.Uninstall ISC INN (innd) from affected systems if the service is not required.
- Compensating control
Restrict network access to the innd service to trusted hosts/networks using firewall rules or ACLs; block remote access to the service until a fix is applied.
- Operational
Stop and disable the innd service on affected hosts until a patched/fixed version is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0472?
CVE-2000-0472 is considered a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2000-0472?
To fix CVE-2000-0472, upgrade to a version of ISC INN that is not vulnerable, such as 2.2.3 or later.
What software is affected by CVE-2000-0472?
CVE-2000-0472 affects ISC INN versions 2.0, 2.1, 2.2, 2.2.1, and 2.2.2.
Can CVE-2000-0472 be exploited remotely?
Yes, CVE-2000-0472 can be exploited remotely by sending a specially crafted cancel request.
What kind of attack is associated with CVE-2000-0472?
CVE-2000-0472 is associated with buffer overflow attacks that could lead to arbitrary command execution.