Description
Buffer overflow of rlogin program using TERM environmental variable.
Product(s):
- Bsdi Bsd Os 1.1
- Bsdi Bsd Os 2.0.1
- Bsdi Bsd Os 2.0
- Bsdi Bsd Os 2.1
- Debian Debian Linux 0.93
- Digital Equipment Corporation Ultrix
- FreeBSD 1.1.5.1
- FreeBSD 2.0.5
- FreeBSD 2.0
- FreeBSD 2.1.0
- FreeBSD 2.1.5
- HP HP-UX 10.00
- HP HP-UX 10.01
- HP HP-UX 10.8
- HP HP-UX 10.9
- HP HP-UX 10.10
- HP HP-UX 10.16
- HP HP-UX 10.20
- HP HP-UX 10.24
- HP HP-UX 10.30
- HP HP-UX 10.34
- IBM AIX 3.2
- IBM AIX 4.1.1
- IBM AIX 4.1.2
- IBM AIX 4.1.3
- IBM AIX 4.1.4
- IBM AIX 4.1.5
- IBM AIX 4.1
- NetBSD 1.0
- NetBSD 1.1
- NeXT NeXTSTEP
- Oracle Solaris
- Oracle Solaris SPARC
- Oracle Solaris on x64
- Oracle Solaris 2.5.1
- Oracle Solaris 2.6
- Oracle Solaris 7.0
- Oracle Solaris 8
- Sun SunOS 4.1.3u1
- Sun SunOS 4.1.4
- Sun Microsystems Solaris 2.3
- Sun Microsystems Solaris 2.4
- Sun Microsystems Solaris 2.5.1
- Sun Microsystems Solaris 2.5
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-1999-0046, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-1999-0046 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.
References:
- http://webappsec.pbworks.com/Buffer-Overflow
- https://capec.mitre.org/data/definitions/10.html
- https://capec.mitre.org/data/definitions/100.html
- https://capec.mitre.org/data/definitions/14.html
- https://capec.mitre.org/data/definitions/24.html
- https://capec.mitre.org/data/definitions/42.html
- https://capec.mitre.org/data/definitions/44.html
- https://capec.mitre.org/data/definitions/45.html
- https://capec.mitre.org/data/definitions/46.html
- https://capec.mitre.org/data/definitions/47.html
- https://capec.mitre.org/data/definitions/67.html
- https://capec.mitre.org/data/definitions/8.html
- https://capec.mitre.org/data/definitions/9.html
- https://capec.mitre.org/data/definitions/92.html
- https://nvd.nist.gov/vuln/detail/CVE-1999-0046