CVE-1999-0214: Critical severity Sun SunOS vulnerability
Denial of service by sending forged ICMP unreachable packets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the host-based firewall on SunOS systems to drop or rate-limit ICMP Type 3 (destination unreachable) packets to reduce the impact of forged ICMP unreachable packets.
SunOS host firewall drop ICMP destination-unreachable (Type 3) = enabled / rate-limited - Compensating control
At the network perimeter, block or rate-limit forged ICMP destination-unreachable packets and implement ingress source-address validation (anti-spoofing) on routers/firewalls to prevent spoofed ICMP unreachable traffic from reaching SunOS hosts.
- Operational
Monitor network traffic and host logs for spikes in ICMP unreachable messages; if an attack is detected, isolate affected hosts from the network for investigation and apply network-level filtering to block the malicious traffic.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0214?
CVE-1999-0214 is classified as a denial of service vulnerability.
How do I fix CVE-1999-0214?
To mitigate CVE-1999-0214, ensure that your SunOS system is updated to a version that is not affected by this vulnerability.
What impact does CVE-1999-0214 have on affected systems?
CVE-1999-0214 can cause affected systems to become unreachable due to the denial of service.
Which versions of SunOS are affected by CVE-1999-0214?
CVE-1999-0214 affects SunOS versions 4.1, 4.1.1, and 4.1.2.
What type of attack is associated with CVE-1999-0214?
CVE-1999-0214 is associated with attacks that involve sending forged ICMP unreachable packets.