Junglewise Threat Intelligence

CVE-1999-0247: ISC InterNetNews buffer overflow in nnrpd

CVE-1999-0247 · Severity: high · CVSS 7.5 · Published 1997-07-21

Technologies: Isc InterNetNews. Vendors: Isc.

Executive brief

A vulnerability exists in the InterNetNews (INN) server software, which is used to manage Usenet news feeds. An attacker can exploit a flaw in the news reader daemon to take control of the server and execute unauthorized commands. This could lead to a complete system compromise, data theft, or disruption of news services.

Technical details

A classic buffer overflow vulnerability exists in the nnrpd (NetNews Remote Protocol Daemon) component of InterNetNews (INN) versions 1.6 and earlier. The flaw is triggered during the handling of client requests, where insufficient bounds checking allows an attacker to overwrite memory. A remote, unauthenticated attacker can exploit this by sending specially crafted input to the NNTP service. Successful exploitation grants the attacker the ability to execute arbitrary code with the privileges of the nnrpd process, typically leading to full system access. Users are advised to upgrade to a patched version of INN.

Affected products

  • ISC InterNetNews (INN) Up to 1.6

Timeline

  • 1997-07-21: disclosed: Initial vulnerability publication

References

Related threats