Vulnerability record · CVE-1999-0661 · published 1 January 1999
CVE-1999-0661: Trojanized software distributions across multiple Unix packages
CVE-1999-0661 covers a set of Unix software packages that were replaced with Trojan Horse versions at their distribution points, including TCP Wrappers 7.6, util-linux 2.9g, wuftpd 2.2 and 2.1f, ircII 2.2.9, OpenSSH 3.4p1, and Sendmail 8.12.6. Because the compromised code was distributed through trusted channels, anyone installing those versions received attacker-modified binaries rather than the legitimate software. The record is a broad umbrella entry rather than a single code defect, and it lists no vendor or product metadata.
Description
A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw yields full root-level compromise with a network vector and high EPSS, but it requires the victim to install a trojanized package, and the record lacks product and version detail beyond the listed packages.
What it is
CVE-1999-0661 covers a set of Unix software packages that were replaced with Trojan Horse versions at their distribution points, including TCP Wrappers 7.6, util-linux 2.9g, wuftpd 2.2 and 2.1f, ircII 2.2.9, OpenSSH 3.4p1, and Sendmail 8.12.6. Because the compromised code was distributed through trusted channels, anyone installing those versions received attacker-modified binaries rather than the legitimate software. The record is a broad umbrella entry rather than a single code defect, and it lists no vendor or product metadata.
Impact
An attacker who controls the trojanized distribution gains whatever privileges the replaced software runs with, which for daemons like wuftpd, OpenSSH, and Sendmail is typically root. That allows full compromise of confidentiality, integrity, and availability on affected hosts.
Attack surface
The vector is network-reachable (AV:N/AC:L/Au:N) with no authentication or user interaction required at the protocol level, but the actual delivery path is the software supply chain: a user or administrator downloads and installs the trojanized package. The flaw is not remotely triggered against a running service in the usual sense; it is introduced before or during installation.
Exploitation
The record is not listed in CISA KEV and has no exploit tags on its references, but EPSS is high at 0.54244 (99th percentile), indicating elevated predicted exploitation activity. No ransomware group associations are documented.
What to do
- Replace any installed copies of the listed versions (TCP Wrappers 7.6, util-linux 2.9g, wuftpd 2.2/2.1f, ircII 2.2.9, OpenSSH 3.4p1, Sendmail 8.12.6) with versions obtained from a verified, trusted source.
- Verify package integrity using vendor cryptographic signatures or published checksums before installation.
- Rebuild or reinstall affected hosts from known-good media rather than attempting to clean a trojanized system in place.
- Restrict outbound and inbound software acquisition to approved mirrors and internal repositories.
- Review CERT advisories CA-1994-07, CA-1994-14, CA-1999-01, CA-1999-02, and CA-2002-28 for the specific distribution-point compromises.
Detection
- Compare installed binary hashes for the listed packages against vendor-published checksums or known-good baselines.
- Audit package installation logs and repository sources for downloads from unofficial or unexpected mirrors.
- Monitor for unexpected outbound connections or processes spawned by wuftpd, OpenSSH, Sendmail, or ircII.
- Check file modification times and ownership on the affected binaries for anomalies inconsistent with normal patching.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
References
Track CVE-1999-0661 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-1999-0661), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.