Search

published date: December 4, 1996

CVE-1999-0043 : Command Execution Vulnerability

Description

Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

Product(s):

  • ISC INN 1.4sec2
  • ISC INN 1.4sec
  • ISC INN 1.4unoff3
  • ISC INN 1.4unoff4
  • ISC INN 1.5
  • Netscape News Server 1.1

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-1999-0043, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-1999-0043 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?