← Vulnerability feed

Vulnerability record · CVE-1999-0439 · published 5 April 1999

CVE-1999-0439: Procmail vulnerability

Procmail · Procmail

Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.

7.5 CVSS 2.0 High EPSS 2.5% · top 15.7%
7.5CVSS 2.0 base score
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-0439 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2001-0850Caldera openlinux vulnerabilityA configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local …EPSS 2.3%10.0CVE-2000-0917LPRng use_syslog format string allows remote command executionLPRng 3.6.24 contains a format string vulnerability in the use_syslog() function. Because the flaw is remotely reachable and leads to arbitrary comma…EPSS 79%analysed10.0CVE-2000-0844Caldera openlinux ebuilder permissions and access controls vulnerabilitySome functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to exec…EPSS 16%10.0CVE-2000-0491Gnome gdm vulnerabilityBuffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of s…EPSS 18%10.0CVE-1999-0879Bsdi bsd os vulnerabilityBuffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.EPSS 9.7%10.0CVE-2000-0374Caldera openlinux vulnerabilityThe default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allow…EPSS 4.3%10.0CVE-1999-0368Proftpd project proftpd vulnerabilityBuffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.EPSS 40%10.0CVE-2000-0370Caldera openlinux vulnerabilityThe debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.EPSS 4.8%

Source: NIST National Vulnerability Database (record CVE-1999-0439), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.