CVE-1999-0323: Critical severity NetBSD NetBSD vulnerability
FreeBSD mmap function allows users to modify append-only or immutable files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Until a vendor patch is available, isolate affected FreeBSD systems (FreeBSD Kernel) from untrusted users and networks. Restrict interactive and unprivileged code execution on those hosts, and block or limit access to services that allow user-supplied code or memory mappings from untrusted sources.
- Operational
Audit and continuously monitor append-only and immutable files on affected systems for unexpected changes. Verify file flags/attributes on critical files, compare against known-good backups, and restore from backups if unauthorized modifications are detected.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0323?
CVE-1999-0323 is considered a moderate risk vulnerability due to its potential exploitation leading to unauthorized file modifications.
How do I fix CVE-1999-0323?
To mitigate CVE-1999-0323, update to the latest versions of FreeBSD, OpenBSD, NetBSD, or BSDI that do not include this vulnerability.
What systems are affected by CVE-1999-0323?
CVE-1999-0323 affects FreeBSD 2.2, OpenBSD 2.2, NetBSD 2.0.4, and BSDI 3.0.
What are the implications of CVE-1999-0323?
The implications of CVE-1999-0323 include the ability for unauthorized users to modify files that are meant to be append-only or immutable.
Is there a patch available for CVE-1999-0323?
Yes, patches are provided in the official releases following the identification of CVE-1999-0323, so ensure your system is updated.