CVE-1999-0305: Medium severity FreeBSD FreeBSD vulnerability

Published Feb 1, 1998
·
Updated

The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.

Affected Software

6 affected components
FreeBSD FreeBSD=2.2.5
OpenBSD OpenBSD=2.1
OpenBSD OpenBSD=2.2
OpenBSD OpenBSD=2.0
FreeBSD FreeBSD=2.2
BSDI Bsd Os

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable source routing by setting the sysctl variable 'dosourceroute' to 0 on affected BSD systems (OpenBSD, FreeBSD, BSDI).

    BSD sysctl facility dosourceroute = 0
  2. Configuration

    Disable IP forwarding by setting the sysctl variable 'forwarding' to 0 on affected BSD systems (OpenBSD, FreeBSD, BSDI).

    BSD sysctl facility forwarding = 0
  3. Compensating control

    Block or drop source-routed packets at network perimeter devices (firewalls/routers) to prevent spoofed TCP connections until systems are patched or vendor fixes are available.

Event History

Feb 1, 1998
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Sep 29, 1999
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-0305?

CVE-1999-0305 has a high severity rating due to its potential for allowing remote attackers to spoof TCP connections.

2

How do I fix CVE-1999-0305?

To fix CVE-1999-0305, ensure that source routing is disabled in your system configuration.

3

Which systems are affected by CVE-1999-0305?

CVE-1999-0305 affects OpenBSD versions 2.0-2.2 and FreeBSD versions 2.2-2.2.5.

4

Can CVE-1999-0305 be exploited remotely?

Yes, CVE-1999-0305 can be exploited remotely due to improper restrictions on source routed packets.

5

What type of attack does CVE-1999-0305 facilitate?

CVE-1999-0305 facilitates TCP spoofing attacks, allowing attackers to intercept or manipulate network traffic.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203