CVE-1999-0052: Null Pointer Dereference
IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
At the network perimeter (firewall/router), drop or block fragmented IP packets destined for affected hosts to mitigate IP-fragmentation-based denial-of-service against FreeBSD systems.
- Operational
If an affected host crashes, reboot to restore service and collect kernel crash dumps and logs for analysis. Monitor systems for repeated crashes and track vendor security advisories for FreeBSD/OpenBSD/BSDI; apply any published patches as soon as they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0052?
CVE-1999-0052 has a severity rating classified as a denial of service vulnerability that can crash systems.
How do I fix CVE-1999-0052?
To address CVE-1999-0052, users should upgrade their FreeBSD or OpenBSD installations to versions that do not have this vulnerability.
Which systems are affected by CVE-1999-0052?
CVE-1999-0052 affects various versions of FreeBSD and OpenBSD, including FreeBSD 1.1.5.1, 2.0, 2.2.2, and others.
What type of attack does CVE-1999-0052 represent?
CVE-1999-0052 represents a remote denial of service attack that exploits IP fragmentation.
Can CVE-1999-0052 be exploited remotely?
Yes, CVE-1999-0052 can be exploited by remote attackers without prior authentication.