Junglewise Threat Intelligence

CVE-1999-0868: ISC INN and ucbmail command injection via shell metacharacters

CVE-1999-0868 · Severity: high · CVSS 7.2 · Published 1997-02-20

Technologies: Isc InterNetNews. Vendors: Isc.

Executive brief

A vulnerability in the InterNetNews (INN) server and the ucbmail utility allows remote attackers to execute unauthorized commands on the server. By sending a specially crafted news control message, an attacker can gain the same privileges as the news service, potentially leading to full system compromise or data theft. This issue is particularly serious because it can affect servers even if they are protected behind a corporate firewall.

Technical details

The vulnerability exists because the InterNetNews (INN) daemon (innd) passes data from news control messages (such as 'newgroup' or 'rmgroup') to the ucbmail program without sufficient sanitization of shell metacharacters. While INN attempts some filtering, ucbmail lacks its own checks and passes the malicious data directly to a shell for processing. An attacker with the ability to send Usenet messages can exploit this to execute arbitrary commands with the privileges of the 'innd' process. This occurs before authorization checks like PGP verification are performed. The issue is addressed by upgrading to INN 1.5.1 and applying the security-patch.04 provided by the maintainers.

Affected products

  • ISC INN (InterNetNews) 1.5.1 and earlier
  • UC Berkeley ucbmail

Timeline

  • 1997-02-20: advisory: Original CERT advisory CA-97.08 published
  • 1997-04-03: advisory: Advisory revised to include ucbmail vulnerability (Topic 2)

References

Related threats