PT-1999-1660 · Freebsd+1 · Freebsd+1
Published
1999-12-31
·
Updated
2016-10-18
·
CVE-1999-1339
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Linux versions prior to 2.2.10
FreeBSD version 3.2
Description:
The issue occurs when Network Address Translation (NAT) is enabled, allowing remote attackers to cause a denial of service, resulting in a kernel panic. This can be achieved via a ping command with the record route option.
Recommendations:
For Linux versions prior to 2.2.10, consider disabling NAT or upgrading to a newer version to mitigate the risk.
For FreeBSD version 3.2, restrict the use of ipfw to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd
Linux