CVE-1999-0015: Medium severity Microsoft Windows NT vulnerability
Teardrop IP denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure perimeter firewall or router to drop IP packets that contain overlapping or malformed fragments (Teardrop-style fragments). If a specific vendor setting exists, enable it to reject fragmented packets with overlapping offsets.
Perimeter firewall / router drop_overlapping_ip_fragments = enabled - Compensating control
At the network edge, block or rate-limit incoming fragmented IP traffic and deploy IDS/IPS rules to detect and drop Teardrop/overlapping-fragment attacks to protect affected hosts (HPE HP-UX, Windows 9x, Windows NT, NetBSD current, SunOS). Restrict external access to vulnerable systems until mitigations are applied.
- Operational
Monitor network logs for fragmented packets with overlapping offsets, investigate any detections, and apply vendor-supplied patches or updates for the listed affected operating systems as they become available. Isolate or take affected hosts offline if they are actively being exploited until remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0015?
CVE-1999-0015 is classified as a denial of service vulnerability that can disrupt network communications.
How do I fix CVE-1999-0015?
To mitigate CVE-1999-0015, ensure that networking equipment and operating systems are patched and configured to block malformed IP packets.
Which systems are affected by CVE-1999-0015?
CVE-1999-0015 affects various versions of HPE HP-UX, Microsoft Windows, NetBSD, and SunOS.
What type of attack does CVE-1999-0015 enable?
CVE-1999-0015 enables a teardrop attack which can cause target systems to crash or become unresponsive.
Is CVE-1999-0015 still a concern today?
While CVE-1999-0015 is an older vulnerability, it can still pose risks for unpatched legacy systems still in operation.