CVE-1999-0357: Medium severity Microsoft Windows 98 vulnerability
Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block or filter 'oshare' packets at the network perimeter (firewall/ACL) to prevent crafted oshare packets from reaching Windows 9x hosts.
- Compensating control
Filter or drop fragmented IP packets with suspicious or invalid fragmentation offsets at routers/firewalls to mitigate attacks that rely on malformed fragmentation.
- Operational
Isolate Windows 9x systems from untrusted networks until mitigations are in place; monitor and log occurrences of malformed 'oshare' or fragmented packets and apply any vendor-supplied fixes when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0357?
CVE-1999-0357 is classified as a denial of service vulnerability.
How do I fix CVE-1999-0357?
To mitigate CVE-1999-0357, it is recommended to upgrade your operating system to a version that does not contain this vulnerability.
What systems are affected by CVE-1999-0357?
CVE-1999-0357 specifically affects Microsoft Windows 98 Gold edition.
What type of attack is CVE-1999-0357?
CVE-1999-0357 involves remote attackers sending crafted 'oshare' packets to cause a denial of service.
Is CVE-1999-0357 still a threat today?
While CVE-1999-0357 primarily affects outdated systems, any legacy systems still using Windows 98 could be vulnerable.