Vulnerability Name: | CVE-1999-0305 (CCN-736) | ||||||||
Assigned: | 1998-02-01 | ||||||||
Published: | 1998-02-01 | ||||||||
Updated: | 2018-05-03 | ||||||||
Summary: | The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-1999-0305 Source: CCN Type: OpenBSD Security Advisory, February 15, 1998 IP Source Routing Problem Source: MISC Type: UNKNOWN http://www.openbsd.org/advisories/sourceroute.txt Source: CCN Type: OpenBSD Security Advisory, February 19, 1998 OpenBSD 2.2 release errata & patch list (search for sourceroute) Source: OSVDB Type: UNKNOWN 11502 Source: CCN Type: OSVDB ID: 11502 Multiple BSD sysctl Control Failure Source Routing Attack Source: XF Type: UNKNOWN bsd-sourceroute(736) Source: XF Type: UNKNOWN bsd-sourceroute(736) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |