CVE-1999-0265: Input Validation
ICMP redirect messages may crash or lock up a host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If supported, disable processing/acceptance of ICMP redirect messages on the Microware OS-9 network stack to prevent crashes or lockups.
Microware OS-9 ICMP redirect processing = disabled - Configuration
If supported, disable processing/acceptance of ICMP redirect messages on the host or network stack running the Novell NetWare FTP Server to prevent crashes or lockups.
Novell NetWare FTP Server ICMP redirect processing = disabled - Compensating control
Block or filter ICMP Redirect (ICMP Type 5) messages to the affected hosts at perimeter and internal firewalls/routers to prevent malicious or malformed ICMP redirects from reaching them.
- Operational
Isolate affected hosts from the network until mitigations are applied. If a host has crashed or locked due to ICMP redirects, reboot the host, apply the mitigations above, and monitor for recurrence.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0265?
CVE-1999-0265 has a high severity level as it can crash or lock up a host.
Which software versions are affected by CVE-1999-0265?
CVE-1999-0265 affects Microware OS-9 and Novell NetWare 3.12.
How do I fix CVE-1999-0265?
To fix CVE-1999-0265, update to the latest patches provided by the software vendor.
What type of attack does CVE-1999-0265 involve?
CVE-1999-0265 involves ICMP redirect messages which can be exploited to crash systems.
Can CVE-1999-0265 be exploited remotely?
Yes, CVE-1999-0265 can potentially be exploited remotely through ICMP traffic.