CVE-1999-0043 describes a critical command injection vulnerability in the INN daemon (innd) version 1.5, affecting various Linux distributions including Red Hat, Caldera, and Netscape. This flaw allows unauthenticated attackers to execute arbitrary commands remotely by injecting shell metacharacters into "newgroup" and "rmgroup" control messages. With a CVSS score of 9.8 (CRITICAL), successful exploitation grants full confidentiality, integrity, and availability impact due to the low attack complexity and network-based vector. While not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion, though no public exploit code or active exploitation has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4secCPE matchmatch criteria | cpe:2.3:a:isc:inn:1.4sec:*:*:*:*:*:*:* | ||
1.4sec2CPE matchmatch criteria | cpe:2.3:a:isc:inn:1.4sec2:*:*:*:*:*:*:* | ||
1.4unoff3CPE matchmatch criteria | cpe:2.3:a:isc:inn:1.4unoff3:*:*:*:*:*:*:* | ||
1.4unoff4CPE matchmatch criteria | cpe:2.3:a:isc:inn:1.4unoff4:*:*:*:*:*:*:* | ||
1.5CPE matchmatch criteria | cpe:2.3:a:isc:inn:1.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.